firecrawl
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
firecrawl-clipackage from the official npm registry. This is a legitimate dependency for the skill's core functionality. - Evidence:
npm install -g firecrawl-cli@1.8.0inrules/install.md. - Evidence:
npx -y firecrawl-cli -yinrules/install.md. - [PROMPT_INJECTION]: The skill handles untrusted third-party data by scraping and crawling external websites, which presents a surface for indirect prompt injection.
- Ingestion points: Commands such as
scrape,search, andcrawlfetch content from user-provided or discovered URLs into the agent's environment. - Boundary markers: The instructions mandate isolating output in a
.firecrawl/directory and recommend incremental reading tools likegrepandheadto avoid direct context injection. - Capability inventory: The skill utilizes
firecrawlandnpxcommands for network access and file system writes. - Sanitization:
rules/security.mdprovides explicit guidance to ignore any instructions found within the fetched web content and treat it as untrusted data.
Audit Metadata