skills/fastcrw/crw/crw-research/Gen Agent Trust Hub

crw-research

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to the vendor's API at api.fastcrw.com to search for academic papers and explore citation graphs. These operations use the vendor's infrastructure to fulfill the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles and processes external data retrieved from API responses, which introduces a potential surface for indirect prompt injection.
  • Ingestion points: Data enters the agent's context through JSON responses from api.fastcrw.com via curl commands.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved API content as untrusted data.
  • Capability inventory: The skill utilizes Bash(curl) for network retrieval and Bash(jq) for processing the resulting data.
  • Sanitization: The skill extraction is limited to specific fields (results[].ids.arxiv) using jq, which provides structural validation, but no content-level sanitization is performed on the extracted strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 AM
Security Audit — agent-trust-hub — crw-research