firecrawl-deep-research
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of data from the open web, which serves as a potential vector for indirect prompt injection attacks.
- Ingestion points: Data is collected from the 'open web' through the 'Firecrawl search and scrape' process described in the Collection Plan section of SKILL.md.
- Boundary markers: The instructions do not define explicit boundary markers or provide specific 'ignore' directives to the agent for content found within the scraped web data.
- Capability inventory: The skill utilizes network-based search and scrape tools and generates structured markdown reports. It does not appear to use dynamic code execution or privileged file system access.
- Sanitization: There is no mention of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent.
Audit Metadata