skills/fastcrw/crw/crw-search/Gen Agent Trust Hub

crw-search

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web search results (titles, snippets, and descriptions) and provides it to the agent, creating a potential surface for indirect prompt injection attacks. \n
  • Ingestion points: Results returned by crw search and scraped content from the scrapeOptions parameter. \n
  • Boundary markers: The skill does not specify the use of delimiters or instructions to ignore embedded commands within the external data. \n
  • Capability inventory: The skill uses the Bash tool to execute commands and has Read access to the filesystem. \n
  • Sanitization: No explicit filtering or sanitization of search results is mentioned before they are interpolated into the agent context. \n- [COMMAND_EXECUTION]: The skill utilizes shell execution for its core functionality, which involves passing user-influenced search queries to the crw binary and curl. \n
  • Evidence: The skill uses Bash to run crw search and curl for API interaction, which requires careful handling of user inputs to prevent shell injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 AM
Security Audit — agent-trust-hub — crw-search