firecrawl-tools
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites, creating an attack surface for indirect prompt injection. * Ingestion points: Content is brought into the context via firecrawl_scrape, firecrawl_crawl, and firecrawl_extract in SKILL.md. * Boundary markers: No delimiters or instructions are provided to help the agent distinguish between its own instructions and potentially malicious commands embedded in the scraped web content. * Capability inventory: The agent has access to file system tools (Glob, Grep, Read) and web scraping capabilities which could be manipulated by adversarial content. * Sanitization: There is no requirement or guidance for sanitizing the ingested content before the agent processes or acts upon it.
Audit Metadata