firecrawl-scraper
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to install a package from an external GitHub repository (
BenedictKing/firecrawl-scraper) usingnpx. This involves downloading and executing third-party code that is not verified as part of the primary skill package. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to scrape and parse external web content, including PDFs and full websites, creating a surface for indirect prompt injection where malicious instructions could influence the agent's behavior.
- Ingestion points: External web content, screenshots, and PDF files processed via the Firecrawl API (SKILL.md).
- Boundary markers: Absent. The documentation does not specify delimiters or instructions for the agent to distinguish between its core logic and data retrieved from the web.
- Capability inventory: The skill facilitates deep content extraction, browser interaction (clicking/scrolling), and parsing of external files.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent.
Audit Metadata