firecrawl-lead-research

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is entirely aligned with its described purpose of lead research and intelligence gathering.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the public web via Firecrawl. While this presents an attack surface where processed websites could contain instructions for the AI, this behavior is central to the tool's intended use case.
  • Ingestion points: Web search results and page content scraped through Firecrawl (SKILL.md).
  • Boundary markers: No delimiters or specific 'ignore' instructions for the scraped content are present.
  • Capability inventory: Tool usage is limited to Firecrawl search and scrape; output is limited to markdown report generation.
  • Sanitization: No explicit filtering or sanitization of ingested content is described.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses an input for the Firecrawl API key and does not access sensitive system files or local credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-lead-research