skills/fastcrw/crw/crw-extract/Gen Agent Trust Hub

crw-extract

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from arbitrary external URLs, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The crw scrape CLI command, crw_scrape MCP tool, and REST API endpoints (/v1/scrape, /v2/extract) documented in SKILL.md are used to fetch content from the web.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to help the underlying LLM distinguish between the target data and potential malicious instructions embedded within the scraped HTML/markdown.
  • Capability inventory: The skill uses Bash(crw:*) and Bash(curl:*) for network operations and the Read tool for accessing local files (e.g., JSON schemas).
  • Sanitization: There is no mention of sanitizing, filtering, or escaping the external content before it is processed by the extraction pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:37 AM
Security Audit — agent-trust-hub — crw-extract