firecrawl

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core web-scraping purpose is coherent, and Firecrawl itself appears to be an official same-org CLI, so this is not malware. However, the skill overreaches by enabling cloud browser automation with logins, routes data through a third-party service, processes untrusted web content with bash available, and includes a mismatched `npx firecrawl` execution path that does not match official docs.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 02:07 AM
Package URL
pkg:socket/skills-sh/marcioaltoe%2Fskills%2Ffirecrawl%2F@3ceaa1d79467ec25dbf9924a15e4d6326ae9dbeb
Security Audit — socket — firecrawl