firecrawl-qa

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon content from external web pages, creating a risk of indirect prompt injection where a malicious site could influence agent behavior.
  • Ingestion points: Untrusted data enters the agent context via 'Firecrawl map', 'Firecrawl browser', and scrape tools as described in the Collection Plan in SKILL.md.
  • Boundary markers: No boundary markers or 'ignore embedded instructions' warnings are present to isolate external site content from skill instructions.
  • Capability inventory: The skill possesses capabilities for browser interaction, form submission, link navigation, and detailed report generation across all sub-agent tasks.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — firecrawl-qa