firecrawl

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the firecrawl-cli package from the official npm registry. This is a legitimate dependency for the skill's core functionality.
  • Evidence: npm install -g firecrawl-cli@1.8.0 in rules/install.md.
  • Evidence: npx -y firecrawl-cli -y in rules/install.md.
  • [PROMPT_INJECTION]: The skill handles untrusted third-party data by scraping and crawling external websites, which presents a surface for indirect prompt injection.
  • Ingestion points: Commands such as scrape, search, and crawl fetch content from user-provided or discovered URLs into the agent's environment.
  • Boundary markers: The instructions mandate isolating output in a .firecrawl/ directory and recommend incremental reading tools like grep and head to avoid direct context injection.
  • Capability inventory: The skill utilizes firecrawl and npx commands for network access and file system writes.
  • Sanitization: rules/security.md provides explicit guidance to ignore any instructions found within the fetched web content and treat it as untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — firecrawl