scrapfly-crawler

Pass

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for API integration and uses official SDKs without any hidden or malicious code.\n- [EXTERNAL_DOWNLOADS]: Required dependency scrapfly-sdk is the official library provided by the vendor.\n- [COMMAND_EXECUTION]: Network operations are restricted to crawling tasks and API communication, which are necessary for the skill's functionality.\n- [DATA_EXFILTRATION]: Standard file-writing operations are included for saving crawled data, which is an expected feature for a web crawler.\n- [PROMPT_INJECTION]: As a web crawler, the skill ingests data from external URLs. This is a known surface for indirect prompt injection, but the risk is inherent to the skill's purpose and no malicious logic was found in the implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 14, 2026, 06:59 AM
Security Audit — agent-trust-hub — scrapfly-crawler