firecrawl-search
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted web sources, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: Untrusted data enters the agent context through the output of
firecrawl searchandfirecrawl scrapecommands, which fetch content from the public internet. - Boundary markers: The skill documentation advises against dumping full responses into the context and suggests using
jqfor selective extraction, which provides a partial boundary, though it does not explicitly warn about embedded instructions in the scraped content. - Capability inventory: The skill has access to the
Bashtool, allowing for command execution and filesystem operations (firecrawl,npx,jq, file redirects). - Sanitization: The use of
jqto extract specific fields (like URLs or titles) acts as a sanitization step, though full-page scraping (--scrape) bypasses this for the main content body. - [EXTERNAL_DOWNLOADS]: The skill utilizes
npx firecrawl-cli, which involves downloading and executing the latest version of the Firecrawl CLI package from the npm registry. - Evidence:
allowed-toolsincludesBash(npx firecrawl-cli *)and the documentation references its use for search and discovery. - [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the
Bashtool to interact with the Firecrawl API and process data. - Evidence: The skill provides numerous examples of bash commands for searching (
firecrawl search), listing tools (firecrawl list), scraping (firecrawl scrape), and sending feedback (firecrawl search-feedback).
Audit Metadata