crw-crawl
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality is to crawl external websites and extract content for processing by the agent. This creates a surface for indirect prompt injection, where malicious instructions could be embedded in the crawled pages to influence the agent's behavior.
- Ingestion points: Data returned by the
crw crawlcommand and thecrw_check_crawl_statusMCP tool (specifically themarkdownandhtmlfields) inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious embedded content when reading from the generated files in the
.crw/directory. - Capability inventory: The skill utilizes
Bash(crw:*),Bash(curl:*), andReadtools, providing the agent with network access and file system interaction capabilities. - Sanitization: There is no mention of sanitizing, filtering, or validating the external content before it is presented to the agent or stored locally.
Audit Metadata