skills/fastcrw/crw/crw-self-host/Gen Agent Trust Hub

crw-self-host

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to fetch and execute an installation script directly from the vendor's domain via piped shell execution: curl -fsSL https://fastcrw.com/install | CRW_BINARY=crw sh.
  • [PRIVILEGE_ESCALATION]: The installation instructions for Debian/Ubuntu systems involve the use of sudo to add GPG keys to protected system directories and to install packages through the system's APT package manager.
  • [EXTERNAL_DOWNLOADS]: The skill triggers downloads of binaries and packages from several sources, including NPM (npx crw-mcp), Cargo (cargo install crw-mcp), Pip (pip install crw), Homebrew, and the vendor's own repository (apt.fastcrw.com).
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for the agent to ingest external, untrusted data from the web.
  • Ingestion points: Untrusted data enters the agent context through the outputs of scrape, crawl, and search operations performed on external URLs and queries.
  • Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following malicious commands embedded within the scraped content.
  • Capability inventory: The skill has access to powerful Bash tools, including crw, curl, docker, and cargo.
  • Sanitization: No explicit sanitization or filtering mechanisms for external web content are described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 AM
Security Audit — agent-trust-hub — crw-self-host