firecrawl-tools

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites, creating an attack surface for indirect prompt injection. * Ingestion points: Content is brought into the context via firecrawl_scrape, firecrawl_crawl, and firecrawl_extract in SKILL.md. * Boundary markers: No delimiters or instructions are provided to help the agent distinguish between its own instructions and potentially malicious commands embedded in the scraped web content. * Capability inventory: The agent has access to file system tools (Glob, Grep, Read) and web scraping capabilities which could be manipulated by adversarial content. * Sanitization: There is no requirement or guidance for sanitizing the ingested content before the agent processes or acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:12 AM
Security Audit — agent-trust-hub — firecrawl-tools