skills/us/crw/crw-extract/Gen Agent Trust Hub

crw-extract

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external websites, which represents a surface for indirect prompt injection.
  • Ingestion points: External web content is retrieved through crw scrape and crw_scrape commands as described in SKILL.md.
  • Boundary markers: The instructions do not define explicit boundary markers or provide warnings to the agent to ignore instructions embedded within the retrieved web content.
  • Capability inventory: The skill utilizes Bash(crw:*), Bash(curl:*), and Read tools, enabling it to execute local CLI commands and read local files (SKILL.md).
  • Sanitization: No explicit sanitization, filtering, or validation of the retrieved web content is documented before the data is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:37 PM
Security Audit — agent-trust-hub — crw-extract