zappos-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a helper script
scripts/crawlora.shwhich executes thecurlcommand to interact with the Crawlora API. The script implements significant security hardening: it validates the format of theCRAWLORA_API_KEYto prevent shell injection, uses a temporary configuration file with restricted permissions to pass sensitive headers (preventing them from appearing in the process list), and uses strict regex-based path validation to ensure only authorized Zappos API endpoints can be called. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.crawlora.netto retrieve product information. This domain is the official infrastructure for the author,crawlora-org, and is used as the primary data source for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Zappos, such as product descriptions and customer reviews, which could theoretically contain malicious instructions.
- Ingestion points: Product search results, brand catalog data, and detailed product responses (including reviews and fit feedback) described in
SKILL.mdandreference/endpoints.md. - Boundary markers: The data is handled as structured JSON, providing basic structural separation, though no specific instructions are given to the agent to disregard embedded commands in the text fields.
- Capability inventory: The skill's capabilities are confined to performing scoped network requests via
curlto the vendor's API and does not have the ability to write files or execute arbitrary code. - Sanitization: The helper script explicitly blocks the
@character in query arguments to preventcurlfrom reading local files and handles POST bodies via stdin to avoid file disclosure vulnerabilities.
Audit Metadata