firecrawl-mcp

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a tool firecrawl_browser_execute that allows for the execution of bash, python, or node code within a persistent browser session. This is an intended feature for automation and multi-step workflows.
  • [CREDENTIALS_UNSAFE]: A hardcoded demo API key (BETA_TEST_KEY_MARCH_2026) is used as a default fallback in the tool scripts. This key is explicitly identified as a testing credential for the vendor's service.
  • [EXTERNAL_DOWNLOADS]: The skill relies on the ai_agent_marketplace Python package, which is the vendor's own library for routing requests to the OneKey Agent Router service.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 08:45 AM
Security Audit — agent-trust-hub — firecrawl-mcp