crw-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents tools designed to ingest untrusted data from external URLs and local files (e.g., PDFs). It specifically addresses this risk by providing a 'Post-filtering strategy stack' to mitigate noise and potential injection from raw web results.
- Ingestion points:
crw searchandcrw scrapemethods inSKILL.md. - Boundary markers: Mentions
truncated: trueflags for MCP calls to signal when content is clipped. - Capability inventory: Includes subprocess execution (Python), file writing to
.crw/or/tmp/, and network operations via CLI, MCP, and REST APIs. - Sanitization: Recommends a multi-layer filtering approach using rank-based triage, regex-based keyword density checks, and LLM-based snippet verification.
- [COMMAND_EXECUTION]: Recommends using the
crwCLI and piping outputs into Python subprocesses for filtering and data transformation. This is a core part of the recommended 'dynamic-search' pattern. - [DYNAMIC_EXECUTION]: Instructions encourage the generation and execution of 'one-shot' Python scripts and shell heredocs to process large search results outside of the primary agent context to save tokens and improve reliability.
- [EXTERNAL_DOWNLOADS]: References several legitimate development dependencies, including the
crw,anthropic, andfirecrawlPython packages. It also describes setting up a local search backend using Docker.
Audit Metadata