firecrawl-lead-gen

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a clear and legitimate workflow for extracting prospect data. Analysis of the instructions and metadata confirms that the behavior matches the stated purpose without any hidden or malicious functionality.
  • [PROMPT_INJECTION]: The skill processes data from external web sources, which is an inherent attack surface for indirect prompt injection.
  • Ingestion points: External prospect databases and web directories accessed via the Firecrawl browser.
  • Boundary markers: The skill includes a 'Quality Bar' requiring that only publicly visible data be extracted and that access controls and CAPTCHAs be respected.
  • Capability inventory: Capabilities are limited to data extraction and formatting into JSON or CSV. There are no instructions for command execution, file system writes, or unauthorized network activity.
  • Sanitization: Data is structured into specific fields for JSON/CSV output, providing protection against schema confusion, though no explicit sanitization logic is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-lead-gen