firecrawl-scraper

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose of converting websites into LLM-ready data and offering autonomous data gathering is broadly aligned with its capabilities and the provided API surface. The primary risks arise from (1) autonomous agent capabilities that can operate with minimal explicit targeting, (2) anti-bot bypass features which could be misused for unauthorized scraping, and (3) potential cost surprises due to stealth pricing and caching defaults. Credential handling is standard (API key in environment), with no evident credential harvesting. Overall, the footprint is coherent with its purpose but leans toward SUSPICIOUS due to strong autonomous data-gathering features and anti-bot bypass capabilities that can be leveraged in ways not always aligned with user intent or compliance. Treat as SUSPICIOUS pending tighter constraints on agent autonomy, explicit user-confirmed targets for autonomous tasks, and clearer governance around anti-bot features.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:55 AM
Package URL
pkg:socket/skills-sh/evolv3ai%2Fclaude-skills-archive%2Ffirecrawl-scraper%2F@83341adaf0a244d17f4a2a4e0f36cd39e9e4c948