skills/fastcrw/crw/crw-scrape/Gen Agent Trust Hub

crw-scrape

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to scrape content from arbitrary URLs, creating a surface for indirect prompt injection where malicious instructions hidden on a website could be executed by the agent.
  • Ingestion points: Content is retrieved from external URLs using the crw scrape tool or the curl command to a REST API and then processed by the agent (SKILL.md).
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to ensure the agent disregards instructions contained within the scraped text.
  • Capability inventory: The skill allows shell command execution via the crw binary and curl, file reading, and writing output to the local file system (SKILL.md).
  • Sanitization: No sanitization, filtering, or validation of the fetched web content is performed before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:18 AM
Security Audit — agent-trust-hub — crw-scrape