firecrawl-scrape

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the internet via the --url and --search parameters, creating a surface where malicious instructions in web content could influence agent behavior.
  • Ingestion points: scripts/mcp/firecrawl_scrape.py in SKILL.md.
  • Boundary markers: None identified in the provided file.
  • Capability inventory: The skill is permitted to use the Bash tool to execute local scripts.
  • Sanitization: No sanitization of scraped content is described.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a Python script located at scripts/mcp/firecrawl_scrape.py using the uv package manager.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — firecrawl-scrape