crewai-task-and-tool-design
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill establishes a robust security posture by mandating that authorization checks be performed in an execution adapter using a principal resolved from the request context, rather than relying on the LLM to follow instructions. This design effectively prevents unauthorized tool use via prompt injection.
- [SAFE]: Data privacy is enforced through strict audit logging rules that explicitly prohibit the capture of unredacted PII, secrets, or raw tool payloads in logs and metrics.
- [SAFE]: The skill provides templates for implementing idempotency in side-effecting tools, requiring a stable key (e.g., correlation ID and argument hash) to ensure that retried operations do not result in duplicate state changes.
- [SAFE]: All references to external standards and dependencies are local or follow standard development practices, with no evidence of remote script execution, obfuscation, or hardcoded credentials.
Audit Metadata