firecrawl

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill enforces a strict 'no-shell' policy, requiring direct process invocation (argument vectors) to prevent shell-based injection attacks when calling the firecrawl CLI.
  • [DATA_EXFILTRATION]: Detailed SSRF protections are mandated, including absolute HTTPS enforcement, host canonicalization, and mandatory DNS resolution checks (A/AAAA) to reject private, local, or reserved IP ranges before any network request is made.
  • [CREDENTIALS_UNSAFE]: Explicit instructions prohibit placing API keys in command-line arguments, shell history, or logs. It mandates the use of secure credential stores or inherited environment variables, specifically warning against the --api-key flag.
  • [EXTERNAL_DOWNLOADS]: The skill correctly identifies that an official SDK may be used only in shipped application code (Path B) and mandates exact version pinning, lockfile verification, and security audits, while prohibiting the skill itself from redistributing external binaries.
  • [PROMPT_INJECTION]: Includes 'Indirect Prompt Injection' mitigations (Category 8) by requiring strict boundary markers and the scrubbing of untrusted data (cookies, auth headers, PII) from CLI output before it enters the agent context.
  • [COMMAND_EXECUTION]: Implements a consent gate for the interact command, ensuring that any stateful or externally visible browser action (like form submission or login) requires explicit user approval.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — firecrawl