firecrawl-map

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external site structures through the firecrawl map command. This represents a potential surface for indirect prompt injection if a targeted website provides malicious or deceptive URL paths to influence subsequent agent actions.
  • Ingestion points: External website structures processed by the Firecrawl CLI (SKILL.md).
  • Boundary markers: None; discovery results are saved to .firecrawl/ for further processing.
  • Capability inventory: Bash command execution for the Firecrawl CLI tool.
  • Sanitization: Standard URL mapping; no specific sanitization logic is described in the prompt template.
  • [EXTERNAL_DOWNLOADS]: The skill allows the use of npx firecrawl-cli, which downloads and executes the vendor's command-line interface. This is a legitimate tool associated with the skill author's infrastructure.
  • [SAFE]: The skill follows standard operational procedures for web mapping, such as saving output to a designated local directory and providing clear usage documentation. No credentials, obfuscation, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 12:31 AM
Security Audit — agent-trust-hub — firecrawl-map