firecrawl

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The three reports converge on a high-level assessment of Firecrawl as a legitimate but powerful web-crawling tool with notable credential handling and data-storage risks. Report 2 provides the most concrete data-flow and credential concerns, making it the strongest basis for an improved security-focused summary. The primary action items are secure credential handling, supplier/package trust verification, access control for local results, and governance around scraping scope and compliance.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/fernando-augustop%2Fclaude-skills%2Ffirecrawl%2F@fdb7f45a272d2ed739b1979c974efdae978bd509