skills/xfstudio/skills/crewai/Gen Agent Trust Hub

crewai

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • PROMPT_INJECTION (LOW): Potential surface for indirect prompt injection through variable interpolation.
  • Ingestion points: User-provided {topic} is interpolated into agent goals in config/agents.yaml and task descriptions in config/tasks.yaml.
  • Boundary markers: None; variables are placed directly within instructions without delimiters or explicit 'ignore' instructions for embedded content.
  • Capability inventory: The framework is designed for multi-agent coordination and tool use; snippets specifically reference SerperDevTool and WebsiteSearchTool in agents.yaml.
  • Sanitization: No sanitization or validation logic is present for the interpolated variables in the provided configuration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:29 PM