skills/felipeangeli/skills/firecrawl/Gen Agent Trust Hub

firecrawl

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the official firecrawl-cli package from the public NPM registry.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute firecrawl CLI commands for scraping, searching, and browser automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest third-party data from the web, which is a known vector for indirect prompt injection. The skill implements a robust security framework in rules/security.md to mitigate this:
  • Ingestion points: Untrusted data enters the environment through the scrape, search, crawl, and browser commands (SKILL.md).
  • Boundary markers: To prevent immediate injection into the agent's context, the skill mandates writing all output to isolated files in the .firecrawl/ directory rather than returning content directly (rules/security.md).
  • Capability inventory: The skill uses the Bash tool to perform operations (SKILL.md).
  • Sanitization: The skill requires quoting URLs to prevent command injection and recommends incremental reading techniques (using grep, head, or wc) to limit the amount of untrusted content processed at once (rules/security.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — firecrawl