firecrawl-workflows
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external web content via Firecrawl, creating an attack surface for indirect prompt injection.\n
- Ingestion points: External web evidence retrieved through the Firecrawl CLI or equivalent tools (as specified in SKILL.md).\n
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the default research process.\n
- Capability inventory: The skill utilizes Firecrawl extraction tools, synthesizes deliverables, and can orchestrate sub-agents to perform parallel tasks.\n
- Sanitization: The instructions do not specify any mechanisms for filtering, escaping, or validating external content before it is processed by the LLM.\n- [SAFE]: The skill references architectural guidelines from a trusted organization (Anthropic) for workflow authoring. These references are used for structural consistency and do not involve the execution of remote code.
Audit Metadata