crw-migrate
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: Analysis of the migration guide and associated examples found no malicious behavior, obfuscation, or safety bypasses. The skill serves its stated purpose as a developer resource.
- [EXTERNAL_DOWNLOADS]: The documentation references the
crw-mcpNode.js package, which is the official integration tool provided by the fastCRW vendor. - [COMMAND_EXECUTION]: The skill provides
curlcommands to interact with the fastCRW API atapi.fastcrw.comfor health checks and service verification. - [INDIRECT_PROMPT_INJECTION]: The skill documents tools for web scraping and data extraction, which involves processing external content. This represents a potential surface for indirect prompt injection, an inherent characteristic of information retrieval services.
- Ingestion points: Web data fetched through scraping endpoints in the SKILL.md examples.
- Boundary markers: The migration guide does not specify the use of delimiters or boundary markers for retrieved data.
- Capability inventory: The skill environment supports network operations via
curland the use of thecrwtoolset. - Sanitization: The documentation does not provide specific guidance on sanitizing the output from scraping operations.
Audit Metadata