firecrawl-deep-research

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of data from the open web, which serves as a potential vector for indirect prompt injection attacks.
  • Ingestion points: Data is collected from the 'open web' through the 'Firecrawl search and scrape' process described in the Collection Plan section of SKILL.md.
  • Boundary markers: The instructions do not define explicit boundary markers or provide specific 'ignore' directives to the agent for content found within the scraped web data.
  • Capability inventory: The skill utilizes network-based search and scrape tools and generates structured markdown reports. It does not appear to use dynamic code execution or privileged file system access.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-deep-research