skills/fastcrw/crw/crw-parse/Gen Agent Trust Hub

crw-parse

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for ingesting external PDF content into the agent's context, creating a potential surface for indirect prompt injection if a processed document contains malicious instructions.
  • Ingestion points: The skill instructions in SKILL.md detail how to read local files and pass their content to the crw_parse_file MCP tool or crw scrape CLI.
  • Boundary markers: There are no explicit instructions or delimiters defined to warn the agent to ignore instructions embedded within the extracted text.
  • Capability inventory: The skill is granted access to Bash and Read tools, which could be targets for manipulation via instructions found in a parsed document.
  • Sanitization: No sanitization or validation of the extracted document content is mentioned before the data is returned to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:18 AM
Security Audit — agent-trust-hub — crw-parse