crw-parse
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for ingesting external PDF content into the agent's context, creating a potential surface for indirect prompt injection if a processed document contains malicious instructions.
- Ingestion points: The skill instructions in
SKILL.mddetail how to read local files and pass their content to thecrw_parse_fileMCP tool orcrw scrapeCLI. - Boundary markers: There are no explicit instructions or delimiters defined to warn the agent to ignore instructions embedded within the extracted text.
- Capability inventory: The skill is granted access to
BashandReadtools, which could be targets for manipulation via instructions found in a parsed document. - Sanitization: No sanitization or validation of the extracted document content is mentioned before the data is returned to the agent's context.
Audit Metadata