crewai-multi-agent
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill's documentation and examples in
SKILL.mdandreferences/tools.mdinclude aCalculatorToolimplementation that uses the Pythoneval()function to process user-supplied strings. - Evidence: In
SKILL.md, theCalculatorTool._runmethod executeseval(expression)directly on the input argument. - Evidence: In
references/tools.md, a similar implementation attempts a basic safety check by looking for alphabetic characters (isalpha()), but this is insufficient to prevent sophisticated Python injection attacks. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to orchestrate agents that ingest data from various untrusted external sources, creating a broad attack surface for indirect prompt injection.
- Ingestion points: The skill utilizes tools such as
ScrapeWebsiteTool,SerperDevTool,PDFSearchTool, andGithubSearchTool(referenced inreferences/tools.md) to pull content from the web, documents, and repositories into the agent's context. - Boundary markers: The provided code examples and task definitions in
SKILL.mdandreferences/yaml-configuration-recommended.mddo not include explicit delimiters or instructions to treat external data as untrusted content. - Capability inventory: The framework includes high-privilege capabilities such as
FileWriterToolfor local file system access,MySQLSearchToolfor database operations, and aCodeInterpreterToolfor executing Python code (referenced inreferences/tools.md). - Sanitization: There is no evidence of sanitization, filtering, or validation of data retrieved from external tools before it is passed to the LLM agents for reasoning and task execution.
Audit Metadata