firecrawl-lead-gen
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a clear and legitimate workflow for extracting prospect data. Analysis of the instructions and metadata confirms that the behavior matches the stated purpose without any hidden or malicious functionality.
- [PROMPT_INJECTION]: The skill processes data from external web sources, which is an inherent attack surface for indirect prompt injection.
- Ingestion points: External prospect databases and web directories accessed via the Firecrawl browser.
- Boundary markers: The skill includes a 'Quality Bar' requiring that only publicly visible data be extracted and that access controls and CAPTCHAs be respected.
- Capability inventory: Capabilities are limited to data extraction and formatting into JSON or CSV. There are no instructions for command execution, file system writes, or unauthorized network activity.
- Sanitization: Data is structured into specific fields for JSON/CSV output, providing protection against schema confusion, though no explicit sanitization logic is defined.
Audit Metadata