firecrawl
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core web-scraping purpose is coherent, and Firecrawl itself appears to be an official same-org CLI, so this is not malware. However, the skill overreaches by enabling cloud browser automation with logins, routes data through a third-party service, processes untrusted web content with bash available, and includes a mismatched `npx firecrawl` execution path that does not match official docs.
Confidence: 85%Severity: 68%
Audit Metadata