zappos-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a helper script scripts/crawlora.sh which executes the curl command to interact with the Crawlora API. The script implements significant security hardening: it validates the format of the CRAWLORA_API_KEY to prevent shell injection, uses a temporary configuration file with restricted permissions to pass sensitive headers (preventing them from appearing in the process list), and uses strict regex-based path validation to ensure only authorized Zappos API endpoints can be called.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to api.crawlora.net to retrieve product information. This domain is the official infrastructure for the author, crawlora-org, and is used as the primary data source for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Zappos, such as product descriptions and customer reviews, which could theoretically contain malicious instructions.
  • Ingestion points: Product search results, brand catalog data, and detailed product responses (including reviews and fit feedback) described in SKILL.md and reference/endpoints.md.
  • Boundary markers: The data is handled as structured JSON, providing basic structural separation, though no specific instructions are given to the agent to disregard embedded commands in the text fields.
  • Capability inventory: The skill's capabilities are confined to performing scoped network requests via curl to the vendor's API and does not have the ability to write files or execute arbitrary code.
  • Sanitization: The helper script explicitly blocks the @ character in query arguments to prevent curl from reading local files and handles POST bodies via stdin to avoid file disclosure vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — zappos-research