skills/firecrawl/cli/firecrawl-search/Gen Agent Trust Hub

firecrawl-search

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted web sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted data enters the agent context through the output of firecrawl search and firecrawl scrape commands, which fetch content from the public internet.
  • Boundary markers: The skill documentation advises against dumping full responses into the context and suggests using jq for selective extraction, which provides a partial boundary, though it does not explicitly warn about embedded instructions in the scraped content.
  • Capability inventory: The skill has access to the Bash tool, allowing for command execution and filesystem operations (firecrawl, npx, jq, file redirects).
  • Sanitization: The use of jq to extract specific fields (like URLs or titles) acts as a sanitization step, though full-page scraping (--scrape) bypasses this for the main content body.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx firecrawl-cli, which involves downloading and executing the latest version of the Firecrawl CLI package from the npm registry.
  • Evidence: allowed-tools includes Bash(npx firecrawl-cli *) and the documentation references its use for search and discovery.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the Bash tool to interact with the Firecrawl API and process data.
  • Evidence: The skill provides numerous examples of bash commands for searching (firecrawl search), listing tools (firecrawl list), scraping (firecrawl scrape), and sending feedback (firecrawl search-feedback).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 11:44 PM
Security Audit — agent-trust-hub — firecrawl-search