crewai-multi-agent

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill's documentation and examples in SKILL.md and references/tools.md include a CalculatorTool implementation that uses the Python eval() function to process user-supplied strings.
  • Evidence: In SKILL.md, the CalculatorTool._run method executes eval(expression) directly on the input argument.
  • Evidence: In references/tools.md, a similar implementation attempts a basic safety check by looking for alphabetic characters (isalpha()), but this is insufficient to prevent sophisticated Python injection attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to orchestrate agents that ingest data from various untrusted external sources, creating a broad attack surface for indirect prompt injection.
  • Ingestion points: The skill utilizes tools such as ScrapeWebsiteTool, SerperDevTool, PDFSearchTool, and GithubSearchTool (referenced in references/tools.md) to pull content from the web, documents, and repositories into the agent's context.
  • Boundary markers: The provided code examples and task definitions in SKILL.md and references/yaml-configuration-recommended.md do not include explicit delimiters or instructions to treat external data as untrusted content.
  • Capability inventory: The framework includes high-privilege capabilities such as FileWriterTool for local file system access, MySQLSearchTool for database operations, and a CodeInterpreterTool for executing Python code (referenced in references/tools.md).
  • Sanitization: There is no evidence of sanitization, filtering, or validation of data retrieved from external tools before it is passed to the LLM agents for reasoning and task execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — crewai-multi-agent