firecrawl-scraper

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to install a package from an external GitHub repository (BenedictKing/firecrawl-scraper) using npx. This involves downloading and executing third-party code that is not verified as part of the primary skill package.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to scrape and parse external web content, including PDFs and full websites, creating a surface for indirect prompt injection where malicious instructions could influence the agent's behavior.
  • Ingestion points: External web content, screenshots, and PDF files processed via the Firecrawl API (SKILL.md).
  • Boundary markers: Absent. The documentation does not specify delimiters or instructions for the agent to distinguish between its core logic and data retrieved from the web.
  • Capability inventory: The skill facilitates deep content extraction, browser interaction (clicking/scrolling), and parsing of external files.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — firecrawl-scraper