firecrawl-workflows

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external web content via Firecrawl, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: External web evidence retrieved through the Firecrawl CLI or equivalent tools (as specified in SKILL.md).\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the default research process.\n
  • Capability inventory: The skill utilizes Firecrawl extraction tools, synthesizes deliverables, and can orchestrate sub-agents to perform parallel tasks.\n
  • Sanitization: The instructions do not specify any mechanisms for filtering, escaping, or validating external content before it is processed by the LLM.\n- [SAFE]: The skill references architectural guidelines from a trusted organization (Anthropic) for workflow authoring. These references are used for structural consistency and do not involve the execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — firecrawl-workflows