firecrawl-shop
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by the official vendor 'firecrawl' and its behaviors, including network access via the Firecrawl API and browser-based cart actions, are aligned with its stated purpose of shopping assistance.
- [PROMPT_INJECTION]: Potential for indirect prompt injection exists due to the processing of untrusted web content from forums and review sites. Ingestion points: Product pages, specifications, and forums (Reddit) via Firecrawl search and scrape. Boundary markers: None defined for the ingested data. Capability inventory: Browser-based cart actions (add to cart). Sanitization: Not specified for the ingested content. The skill mitigates this risk by requiring explicit user approval before any checkout or purchase action.
Audit Metadata