skills/fastcrw/crw/crw-crawl/Gen Agent Trust Hub

crw-crawl

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality is to crawl external websites and extract content for processing by the agent. This creates a surface for indirect prompt injection, where malicious instructions could be embedded in the crawled pages to influence the agent's behavior.
  • Ingestion points: Data returned by the crw crawl command and the crw_check_crawl_status MCP tool (specifically the markdown and html fields) in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious embedded content when reading from the generated files in the .crw/ directory.
  • Capability inventory: The skill utilizes Bash(crw:*), Bash(curl:*), and Read tools, providing the agent with network access and file system interaction capabilities.
  • Sanitization: There is no mention of sanitizing, filtering, or validating the external content before it is presented to the agent or stored locally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:37 AM
Security Audit — agent-trust-hub — crw-crawl