firecrawl-market-research

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for market research and financial analysis, which aligns with the toolset it describes (web scraping and searching).
  • [EXTERNAL_DOWNLOADS]: The skill references official resources from the vendor (firecrawl.dev and the firecrawl-workflows GitHub repository). These are verified vendor-owned domains and repositories used for documentation and source code hosting.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external websites such as investor relations pages, SEC filings, and news portals. This introduces a surface for indirect prompt injection if external content contains malicious instructions. However, the skill includes a 'Quality Bar' section that mandates cross-referencing and source validation, which serves as a mitigation.
  • Ingestion points: External URLs accessed via Firecrawl search, scrape, and browser tools.
  • Boundary markers: Not explicitly defined in the interpolation of scraped data.
  • Capability inventory: Search, scrape, browser interaction, and parallel sub-agent execution.
  • Sanitization: Instructions include cross-referencing key numbers and noting conflicting data across sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-market-research