firecrawl-company-directories

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting data from external websites such as startup directories and category databases. This creates a potential surface for indirect prompt injection, as the agent processes content from untrusted sources to generate structured output.
  • Ingestion points: External directory URLs and company profile pages (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters to isolate the untrusted content or commands to ignore embedded instructions.
  • Capability inventory: Web scraping, data mapping, and structured reporting (Markdown and JSON).
  • Sanitization: No explicit content sanitization or validation steps are outlined in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-company-directories