firecrawl
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the official
firecrawl-clipackage from the public NPM registry. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to executefirecrawlCLI commands for scraping, searching, and browser automation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest third-party data from the web, which is a known vector for indirect prompt injection. The skill implements a robust security framework in
rules/security.mdto mitigate this: - Ingestion points: Untrusted data enters the environment through the
scrape,search,crawl, andbrowsercommands (SKILL.md). - Boundary markers: To prevent immediate injection into the agent's context, the skill mandates writing all output to isolated files in the
.firecrawl/directory rather than returning content directly (rules/security.md). - Capability inventory: The skill uses the
Bashtool to perform operations (SKILL.md). - Sanitization: The skill requires quoting URLs to prevent command injection and recommends incremental reading techniques (using
grep,head, orwc) to limit the amount of untrusted content processed at once (rules/security.md).
Audit Metadata