firecrawl-scrape
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the internet via the
--urland--searchparameters, creating a surface where malicious instructions in web content could influence agent behavior. - Ingestion points:
scripts/mcp/firecrawl_scrape.pyinSKILL.md. - Boundary markers: None identified in the provided file.
- Capability inventory: The skill is permitted to use the
Bashtool to execute local scripts. - Sanitization: No sanitization of scraped content is described.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute a Python script located atscripts/mcp/firecrawl_scrape.pyusing theuvpackage manager.
Audit Metadata