Back to skill

Security audit

Firecrawl Local Search

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward local Firecrawl helper, but it sends arbitrary scrape targets to an unauthenticated HTTP service on a private-network address, so users should review the network exposure before installing.

Install only if you control and trust the Firecrawl service at 192.168.1.2:3002 and understand that target URLs and results are sent over unauthenticated HTTP. Avoid using it with sensitive URLs, credentials in query strings, or untrusted prompts unless you add target allowlists, authentication, and network egress controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/firecrawl_scrape.py:8
Finding

Unrestricted Server-Side URL Retrieval

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/firecrawl_scrape.py:6
Finding

Unauthenticated Cleartext Communication with the Firecrawl API

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents and encourages network access to a local HTTP service but does not declare any explicit tool scope or permissions boundaries. This creates a governance gap: an agent may gain undeclared network capability, making review, policy enforcement, and user consent weaker for data exfiltration or unintended internal network access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and the entire skill documentation are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language policy issue because it effectively forces a locale/language without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill sends user-supplied URLs and potentially retrieved content to an HTTP endpoint on a private network address. Because the service uses plain HTTP and targets an internal IP, it increases the risk of unencrypted data exposure, SSRF-like access to internal resources through the local crawler, and unintended transmission of sensitive browsing targets within a trusted network context.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

1. 网页抓取 (Scrape)

bash
curl -X POST "http://192.168.1.2:3002/v1/scrape" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "formats": ["markdown"]}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's natural-language interface is entirely in Chinese, including the module docstring, function docstring, error messages, and CLI usage text. This imposes a specific language on users without opt-in or any documented region-specific justification, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.