firecrawl-research-papers
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external academic sources which could contain malicious instructions.
- Ingestion points: External content is ingested via
firecrawl_research_read_paper,firecrawl_scrape, andfirecrawl_searchin SKILL.md. - Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions embedded within the research papers or web content.
- Capability inventory: The skill uses findings to generate a literature review but lacks capabilities for command execution, file system modification, or network requests to non-vendor domains using the ingested data.
- Sanitization: There is no mention of sanitizing or validating the content retrieved from external sources before it is processed by the agent.
Audit Metadata