skills/fastcrw/crw/crw-migrate/Gen Agent Trust Hub

crw-migrate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the migration guide and associated examples found no malicious behavior, obfuscation, or safety bypasses. The skill serves its stated purpose as a developer resource.
  • [EXTERNAL_DOWNLOADS]: The documentation references the crw-mcp Node.js package, which is the official integration tool provided by the fastCRW vendor.
  • [COMMAND_EXECUTION]: The skill provides curl commands to interact with the fastCRW API at api.fastcrw.com for health checks and service verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents tools for web scraping and data extraction, which involves processing external content. This represents a potential surface for indirect prompt injection, an inherent characteristic of information retrieval services.
  • Ingestion points: Web data fetched through scraping endpoints in the SKILL.md examples.
  • Boundary markers: The migration guide does not specify the use of delimiters or boundary markers for retrieved data.
  • Capability inventory: The skill environment supports network operations via curl and the use of the crw toolset.
  • Sanitization: The documentation does not provide specific guidance on sanitizing the output from scraping operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 AM
Security Audit — agent-trust-hub — crw-migrate