crw-scrape
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools to scrape content from arbitrary URLs, creating a surface for indirect prompt injection where malicious instructions hidden on a website could be executed by the agent.
- Ingestion points: Content is retrieved from external URLs using the
crw scrapetool or thecurlcommand to a REST API and then processed by the agent (SKILL.md). - Boundary markers: The instructions do not specify any delimiters or safety prompts to ensure the agent disregards instructions contained within the scraped text.
- Capability inventory: The skill allows shell command execution via the
crwbinary andcurl, file reading, and writing output to the local file system (SKILL.md). - Sanitization: No sanitization, filtering, or validation of the fetched web content is performed before it is presented to the agent.
Audit Metadata