firecrawl-scrape
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
firecrawlcommand-line interface ornpx firecrawl-clito perform web scraping operations. These commands are explicitly permitted in theallowed-toolsconfiguration. The skill also suggests using standard shell utilities likeheadandgrepto inspect the results. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external URLs.
- Ingestion points: Data enters the system via
firecrawl scrape "<url>", which fetches content from any user-provided or agent-discovered website. - Boundary markers: The instructions do not define strict boundary markers for the scraped content, though it is converted to markdown to be more legible for the agent.
- Capability inventory: The agent has access to local shell execution (
firecrawl,npx,head,grep) and file system writes (via the-oflag to the.firecrawl/directory). - Sanitization: The Firecrawl service performs sanitization by converting raw HTML and JavaScript-rendered content into clean markdown, which reduces the surface area for direct script execution but does not prevent natural language instructions from appearing in the output.
Audit Metadata