firecrawl-demo-walkthrough
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites during its collection plan. This creates a surface where external web content could potentially contain instructions aimed at the AI agent. The skill attempts to mitigate this through a structured 'Final Deliverable' format and instructions to 'separate observation from opinion,' though it does not use explicit boundary markers for the crawled content.
- [CREDENTIALS_UNSAFE]: The skill requires a 'FIRECRAWL_API_KEY' as a user-provided input for its core operation. It also mentions asking for credentials to access protected product areas for deep walkthroughs. The instructions include a safety guideline advising the agent not to submit real credentials or perform irreversible actions without explicit user permission.
Audit Metadata