firecrawl
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill enforces a strict 'no-shell' policy, requiring direct process invocation (argument vectors) to prevent shell-based injection attacks when calling the
firecrawlCLI. - [DATA_EXFILTRATION]: Detailed SSRF protections are mandated, including absolute HTTPS enforcement, host canonicalization, and mandatory DNS resolution checks (A/AAAA) to reject private, local, or reserved IP ranges before any network request is made.
- [CREDENTIALS_UNSAFE]: Explicit instructions prohibit placing API keys in command-line arguments, shell history, or logs. It mandates the use of secure credential stores or inherited environment variables, specifically warning against the
--api-keyflag. - [EXTERNAL_DOWNLOADS]: The skill correctly identifies that an official SDK may be used only in shipped application code (Path B) and mandates exact version pinning, lockfile verification, and security audits, while prohibiting the skill itself from redistributing external binaries.
- [PROMPT_INJECTION]: Includes 'Indirect Prompt Injection' mitigations (Category 8) by requiring strict boundary markers and the scrubbing of untrusted data (cookies, auth headers, PII) from CLI output before it enters the agent context.
- [COMMAND_EXECUTION]: Implements a consent gate for the
interactcommand, ensuring that any stateful or externally visible browser action (like form submission or login) requires explicit user approval.
Audit Metadata