skills/firecrawl/cli/firecrawl-scrape/Gen Agent Trust Hub

firecrawl-scrape

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the firecrawl command-line interface or npx firecrawl-cli to perform web scraping operations. These commands are explicitly permitted in the allowed-tools configuration. The skill also suggests using standard shell utilities like head and grep to inspect the results.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external URLs.
  • Ingestion points: Data enters the system via firecrawl scrape "<url>", which fetches content from any user-provided or agent-discovered website.
  • Boundary markers: The instructions do not define strict boundary markers for the scraped content, though it is converted to markdown to be more legible for the agent.
  • Capability inventory: The agent has access to local shell execution (firecrawl, npx, head, grep) and file system writes (via the -o flag to the .firecrawl/ directory).
  • Sanitization: The Firecrawl service performs sanitization by converting raw HTML and JavaScript-rendered content into clean markdown, which reduces the surface area for direct script execution but does not prevent natural language instructions from appearing in the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:02 PM
Security Audit — agent-trust-hub — firecrawl-scrape