firecrawl-company-directories
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting data from external websites such as startup directories and category databases. This creates a potential surface for indirect prompt injection, as the agent processes content from untrusted sources to generate structured output.
- Ingestion points: External directory URLs and company profile pages (SKILL.md).
- Boundary markers: The instructions do not define specific delimiters to isolate the untrusted content or commands to ignore embedded instructions.
- Capability inventory: Web scraping, data mapping, and structured reporting (Markdown and JSON).
- Sanitization: No explicit content sanitization or validation steps are outlined in the skill instructions.
Audit Metadata