firecrawl-qa
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon content from external web pages, creating a risk of indirect prompt injection where a malicious site could influence agent behavior.
- Ingestion points: Untrusted data enters the agent context via 'Firecrawl map', 'Firecrawl browser', and scrape tools as described in the Collection Plan in SKILL.md.
- Boundary markers: No boundary markers or 'ignore embedded instructions' warnings are present to isolate external site content from skill instructions.
- Capability inventory: The skill possesses capabilities for browser interaction, form submission, link navigation, and detailed report generation across all sub-agent tasks.
- Sanitization: There is no evidence of sanitization, escaping, or validation of the data retrieved from external sources before it is processed by the agent.
Audit Metadata