crw-search
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web search results (titles, snippets, and descriptions) and provides it to the agent, creating a potential surface for indirect prompt injection attacks. \n
- Ingestion points: Results returned by
crw searchand scraped content from thescrapeOptionsparameter. \n - Boundary markers: The skill does not specify the use of delimiters or instructions to ignore embedded commands within the external data. \n
- Capability inventory: The skill uses the
Bashtool to execute commands and hasReadaccess to the filesystem. \n - Sanitization: No explicit filtering or sanitization of search results is mentioned before they are interpolated into the agent context. \n- [COMMAND_EXECUTION]: The skill utilizes shell execution for its core functionality, which involves passing user-influenced search queries to the
crwbinary andcurl. \n - Evidence: The skill uses
Bashto runcrw searchandcurlfor API interaction, which requires careful handling of user inputs to prevent shell injection.
Audit Metadata