firecrawl-search
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites through search results and full-page scraping, which could contain instructions intended to influence agent behavior.
- Ingestion points: Search results and scraped content returned by the
firecrawltool inSKILL.md. - Capability inventory: Shell command execution via
Bash(firecrawl *)andBash(npx firecrawl *). - Boundary markers: No specific delimiting instructions or warnings for the agent when processing external content are provided in the skill body.
- Sanitization: The skill does not perform explicit sanitization of the scraped markdown or JSON data.
- [COMMAND_EXECUTION]: The skill facilitates the execution of the
firecrawlCLI tool to perform web searches and scrapes. The tool usage is constrained to the primary purpose of the skill. - [EXTERNAL_DOWNLOADS]: The skill uses
npxto fetch and run thefirecrawlpackage from the official npm registry, which is a standard method for utilizing CLI utilities.
Audit Metadata