firecrawl-search

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent: web search plus optional page scraping via Firecrawl's official ecosystem. However, the `npx firecrawl` allowance does not match the documented official package name, creating supply-chain ambiguity, and the skill ingests arbitrary external web content while retaining Bash execution, which raises indirect prompt-injection risk. No clear credential theft, exfiltration, or overtly malicious behavior is present.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 15, 2026, 12:44 AM
Package URL
pkg:socket/skills-sh/firecrawl%2Fcli%2Ffirecrawl-search%2F@41ef6ac9682323c407679f8168a1776f62b3fb14
Security Audit — socket — firecrawl-search