firecrawl
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's SKILL.md explicitly instructs the agent to search, scrape, map, crawl, and interact with arbitrary public URLs (e.g., use of commands like
firecrawl scrape "<url>",search --scrape,crawl, andagenton web pages) and rules/security.md even labels fetched web content "untrusted third-party data", so the agent will ingest and act on open/public web content that could contain indirect prompt-injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata