crw-watch
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web snapshots and uses an 'AI Judge' feature to filter changes based on natural language goals. This creates an attack surface where instructions embedded in the web content could manipulate the AI's output.\n- Ingestion points: Web content is passed through the
currentandpreviousfields inSKILL.md.\n- Boundary markers: The skill does not define specific boundaries or ignore-instructions for the content being processed.\n- Capability inventory: The skill usescurl,Bash, andReadcapabilities, and the AI output is intended to drive alerts and local script actions.\n- Sanitization: The provided scripts usejqfor JSON encoding but lack mechanisms to strip or neutralize prompt injection attempts within the content.
Audit Metadata