firecrawl

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with a web-scraping/search purpose and uses standard npm-based execution, but it expands into transitive skill installation, autonomous extraction jobs, and browser-session code execution while consuming untrusted web content at scale. No clear credential theft or malicious exfiltration is evident, yet the capability mix and indirect prompt-injection exposure make it a medium-risk skill rather than benign.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
Aug 24, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Ffirecrawl%2F@afd19331206ccf277c24914db39838da206b5cc5e13849d65beef6a7961646ca
Security Audit — socket — firecrawl