firecrawl-demo-walkthrough

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Requests a FIRECRAWL_API_KEY as a required input to facilitate interaction with the Firecrawl hosted service. This is standard authentication for the tool's intended use.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from external URLs, which represents a potential surface for indirect prompt injection. This risk is mitigated by explicit instructions directing the agent not to submit credentials or perform irreversible actions without user permission.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:48 PM