firecrawl-research-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of untrusted content from various web sources, creating a surface for indirect prompt injection.
  • Ingestion points: The agent fetches data from external URLs via the Firecrawl API (api.firecrawl.dev), Jina Reader (r.jina.ai), and academic repositories like arXiv.
  • Boundary markers: The processing logic does not specify the use of clear delimiters or instructions for the agent to ignore embedded commands within the scraped content.
  • Capability inventory: The skill utilizes Write, Edit, and Bash capabilities to manage the research corpus and execute processing tools (pandoc, jq, grep).
  • Sanitization: The instructions focus on token trimming for context window management (trimToTokenLimit) but do not include specific sanitization against adversarial content in the scraped markdown.
  • [EXTERNAL_DOWNLOADS]: The skill fetches research data and academic papers from several well-known and legitimate external services.
  • Evidence: Documented integrations with api.firecrawl.dev, r.jina.ai, arxiv.org, doi.org, and api.semanticscholar.org for content retrieval.
  • Verification: All identified sources are standard infrastructure for research and academic workflows.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use standard system utilities to process scraped research data.
  • Tool Usage: Employs curl for API requests, jq for JSON parsing, pandoc for LaTeX-to-Markdown conversion, and grep/cat for file manipulation.
  • System Modifications: Suggests the use of brew install pandoc if the tool is missing, which involves legitimate software installation for the skill's primary purpose.
  • [METADATA_POISONING]: The skill contains instructions for "Self-Evolution," encouraging the agent to modify its own SKILL.md file dynamically.
  • Evidence: A dedicated section titled "Self-Evolving Skill" instructs the agent to "fix this file immediately" if parameters drift or workarounds are required.
  • Context: While intended as a maintenance pattern for improving documentation based on runtime experience, this mechanism technically involves the agent overwriting its own instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:42 PM
Security Audit — agent-trust-hub — firecrawl-research-patterns