firecrawl-website-design-clone

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the firecrawl CLI to perform web scraping operations. This is the primary function of the skill and utilizes the vendor's own infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites, which presents an inherent surface for indirect prompt injection. This risk is consistent with the skill's core purpose of analyzing third-party web content.
  • Ingestion points: Scraped website data, including branding info, images, and HTML content, retrieved via the Firecrawl API (SKILL.md).
  • Boundary markers: None explicitly defined in the instructions for synthesis.
  • Capability inventory: Execution of firecrawl CLI commands and writing to local files (DESIGN.md and .firecrawl/ directory).
  • Sanitization: None specified; the skill relies on the agent's ability to summarize design tokens from the input content.
  • [EXTERNAL_DOWNLOADS]: The skill may download screenshot images from remote URLs (such as signed storage links) returned by the Firecrawl API to store them locally for reference in the documentation. This is a functional requirement for the design extraction process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:35 PM
Security Audit — agent-trust-hub — firecrawl-website-design-clone