crw-extract
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from arbitrary external URLs, creating a surface for indirect prompt injection attacks.
- Ingestion points: The
crw scrapeCLI command,crw_scrapeMCP tool, and REST API endpoints (/v1/scrape,/v2/extract) documented inSKILL.mdare used to fetch content from the web. - Boundary markers: The instructions do not specify any delimiters or safety warnings to help the underlying LLM distinguish between the target data and potential malicious instructions embedded within the scraped HTML/markdown.
- Capability inventory: The skill uses
Bash(crw:*)andBash(curl:*)for network operations and theReadtool for accessing local files (e.g., JSON schemas). - Sanitization: There is no mention of sanitizing, filtering, or escaping the external content before it is processed by the extraction pipeline.
Audit Metadata