firecrawl-scraper
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is installed from a third-party GitHub repository (
BenedictKing/firecrawl-scraper) that is not affiliated with the skill author or a trusted vendor. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to scrape web content and parse PDF documents, which are untrusted external data sources.
- Ingestion points: Website data and PDF files retrieved via the Firecrawl API (SKILL.md).
- Boundary markers: The documentation does not specify the use of delimiters or boundary markers to distinguish untrusted data from instructions.
- Capability inventory: The skill performs automated browsing, scraping, and file parsing (SKILL.md).
- Sanitization: There is no mention of sanitization or filtering logic for the data ingested from the web.
Audit Metadata