skills/fastcrw/crw/crw-dynamic-search/Gen Agent Trust Hub

crw-dynamic-search

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to generate and execute Python scripts at runtime using shell heredocs (python3 << 'PYEOF') and direct command-line execution (python3 -c). This is the primary mechanism used to process and filter web data locally.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands and Python's subprocess module to interact with external tools. It specifically demonstrates using subprocess.check_output to call the crw CLI tool for web searching and scraping operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content fetched from the internet, which presents a surface for indirect prompt injection if a processed website contains malicious instructions designed to subvert the agent's logic.
  • Ingestion points: Untrusted data enters the agent's context through search results and page markdown fetched by the crw tool and processed by Python scripts.
  • Boundary markers: The instructions do not define explicit boundary markers or "ignore instructions" delimiters for the content being processed from the web.
  • Capability inventory: The skill has access to shell execution, file system writes (specifically to the /tmp/ directory), and network operations via the crw CLI.
  • Sanitization: The provided Python templates focus on relevance filtering (keyword matching and snippet length) rather than security-focused sanitization or escaping of the ingested web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:37 AM
Security Audit — agent-trust-hub — crw-dynamic-search