zalando-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local bash script (scripts/crawlora.sh) to perform API requests. This script is well-hardened, featuring validation for allowed paths and methods, and prevents query parameter injection by using curl's URL-encoding features. It also securely manages the API key by writing it to a temporary, restricted configuration file that is automatically deleted on exit.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves product, search, and category data from the vendor-controlled domain api.crawlora.net. These network operations are intrinsic to the skill's function as a fashion marketplace research tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Zalando storefronts through the Crawlora API.
  • Ingestion points: Data enters the agent's context through the output of scripts/crawlora.sh as documented in SKILL.md.
  • Boundary markers: The skill does not currently use specific boundary markers or instructions to isolate the JSON results from the API.
  • Capability inventory: The skill has access to the local shell for running the scripts/crawlora.sh script.
  • Sanitization: The helper script sanitizes all query arguments and rejects suspicious patterns like the '@' character which could be used to trigger unexpected file reads in curl.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — zalando-research