crewai-task-and-tool-design

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a robust security posture by mandating that authorization checks be performed in an execution adapter using a principal resolved from the request context, rather than relying on the LLM to follow instructions. This design effectively prevents unauthorized tool use via prompt injection.
  • [SAFE]: Data privacy is enforced through strict audit logging rules that explicitly prohibit the capture of unredacted PII, secrets, or raw tool payloads in logs and metrics.
  • [SAFE]: The skill provides templates for implementing idempotency in side-effecting tools, requiring a stable key (e.g., correlation ID and argument hash) to ensure that retried operations do not result in duplicate state changes.
  • [SAFE]: All references to external standards and dependencies are local or follow standard development practices, with no evidence of remote script execution, obfuscation, or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — crewai-task-and-tool-design