crewai

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill documentation provides legitimate patterns for building AI agent teams using the CrewAI framework. The code snippets follow official framework documentation standards and contain no malicious logic.
  • [INDIRECT_PROMPT_INJECTION]: The patterns describe agents that process external user input (e.g., the {topic} variable) through multi-agent tasks and search tools. This is an expected functional surface for the framework.
  • Ingestion points: Placeholders in config/agents.yaml and config/tasks.yaml defined in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the provided YAML examples.
  • Capability inventory: The examples include network-enabled tools such as SerperDevTool and WebsiteSearchTool to fetch external content.
  • Sanitization: No input filtering or validation code is present in the demonstrated setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — crewai