crw-self-host
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to fetch and execute an installation script directly from the vendor's domain via piped shell execution:
curl -fsSL https://fastcrw.com/install | CRW_BINARY=crw sh. - [PRIVILEGE_ESCALATION]: The installation instructions for Debian/Ubuntu systems involve the use of
sudoto add GPG keys to protected system directories and to install packages through the system's APT package manager. - [EXTERNAL_DOWNLOADS]: The skill triggers downloads of binaries and packages from several sources, including NPM (
npx crw-mcp), Cargo (cargo install crw-mcp), Pip (pip install crw), Homebrew, and the vendor's own repository (apt.fastcrw.com). - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for the agent to ingest external, untrusted data from the web.
- Ingestion points: Untrusted data enters the agent context through the outputs of
scrape,crawl, andsearchoperations performed on external URLs and queries. - Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following malicious commands embedded within the scraped content.
- Capability inventory: The skill has access to powerful
Bashtools, includingcrw,curl,docker, andcargo. - Sanitization: No explicit sanitization or filtering mechanisms for external web content are described in the instructions.
Audit Metadata