firecrawl-lead-research

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to scrape external websites, news articles, and public profiles to generate intelligence briefs. This creates an attack surface where untrusted data from the web is ingested into the agent's context.
  • Ingestion points: Web content retrieved via Firecrawl search and scrape operations (company websites, news, social profiles).
  • Boundary markers: The instructions do not define specific delimiters or "ignore" instructions to separate scraped content from the agent's core logic.
  • Capability inventory: The skill is primarily informational, but it involves data aggregation and report generation which can be influenced by malicious content found during scraping.
  • Sanitization: No explicit sanitization, filtering, or validation of the retrieved external content is mentioned.
  • [SAFE]: The skill uses official infrastructure and APIs associated with the vendor (Firecrawl). The required API key and homepage references are consistent with the skill's stated purpose of providing lead intelligence through the Firecrawl service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — firecrawl-lead-research