firecrawl-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
firecrawlandnpx firecrawl-clitools to manage web monitoring tasks. These are official resources provided by the skill's vendor and are intended for the skill's primary functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content through an AI change judge, creating an attack surface for indirect prompt injection.\n - Ingestion points: Web content is ingested from external URLs specified via CLI flags in
SKILL.md.\n - Boundary markers: Absent; the instructions do not explicitly provide delimiters to isolate the ingested web content from the AI goal instructions.\n
- Capability inventory: The skill can trigger automated notifications via the
--emailand--webhook-urlflags inSKILL.mdwhen changes are detected.\n - Sanitization: The skill documentation indicates that the change detection and judgment logic are handled server-side by the Firecrawl platform.
Audit Metadata