firecrawl-monitor

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the firecrawl and npx firecrawl-cli tools to manage web monitoring tasks. These are official resources provided by the skill's vendor and are intended for the skill's primary functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content through an AI change judge, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: Web content is ingested from external URLs specified via CLI flags in SKILL.md.\n
  • Boundary markers: Absent; the instructions do not explicitly provide delimiters to isolate the ingested web content from the AI goal instructions.\n
  • Capability inventory: The skill can trigger automated notifications via the --email and --webhook-url flags in SKILL.md when changes are detected.\n
  • Sanitization: The skill documentation indicates that the change detection and judgment logic are handled server-side by the Firecrawl platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 03:42 PM
Security Audit — agent-trust-hub — firecrawl-monitor