crewai
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional content and code examples for the CrewAI framework. Analysis of the instructions, YAML configurations, and Python code snippets revealed no malicious patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface common to multi-agent frameworks that ingest external data.
- Ingestion points: The skill demonstrates agents using
SerperDevToolandWebsiteSearchToolto retrieve content from the internet (SKILL.md). - Boundary markers: Absent; the provided code templates do not explicitly show delimiters or instructions to ignore malicious content within tool outputs.
- Capability inventory: Agents are configured to perform web searches and process the results to generate content (SKILL.md).
- Sanitization: Absent; the skill focuses on framework orchestration rather than input validation or sanitization techniques for retrieved data.
Audit Metadata