firecrawl-knowledge-ingest

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web pages and documentation portals, which introduces a potential surface for indirect prompt injection if the ingested data contains malicious instructions targeting the LLM.
  • Ingestion points: Public or authenticated third-party documentation portals and knowledge bases fetched via the Firecrawl browser workflow (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify any delimiters or safety guidelines directing the agent to disregard instructions contained within the scraped web text.
  • Capability inventory: None. The skill defines natural language workflows and output templates but does not execute local commands, write files, or invoke code execution tools within the provided file.
  • Sanitization: Absent. Content is transformed into markdown and structured JSON without explicit filtering or validation of the text body.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — firecrawl-knowledge-ingest