skills/fastcrw/crw/crw-watch/Gen Agent Trust Hub

crw-watch

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web snapshots and uses an 'AI Judge' feature to filter changes based on natural language goals. This creates an attack surface where instructions embedded in the web content could manipulate the AI's output.\n- Ingestion points: Web content is passed through the current and previous fields in SKILL.md.\n- Boundary markers: The skill does not define specific boundaries or ignore-instructions for the content being processed.\n- Capability inventory: The skill uses curl, Bash, and Read capabilities, and the AI output is intended to drive alerts and local script actions.\n- Sanitization: The provided scripts use jq for JSON encoding but lack mechanisms to strip or neutralize prompt injection attempts within the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 AM
Security Audit — agent-trust-hub — crw-watch