T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/firecrawl_scrape.py:8- Finding
Unrestricted Server-Side URL Retrieval
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a straightforward local Firecrawl helper, but it sends arbitrary scrape targets to an unauthenticated HTTP service on a private-network address, so users should review the network exposure before installing.
Install only if you control and trust the Firecrawl service at 192.168.1.2:3002 and understand that target URLs and results are sent over unauthenticated HTTP. Avoid using it with sensitive URLs, credentials in query strings, or untrusted prompts unless you add target allowlists, authentication, and network egress controls.
scripts/firecrawl_scrape.py:8Unrestricted Server-Side URL Retrieval
scripts/firecrawl_scrape.py:6Unauthenticated Cleartext Communication with the Firecrawl API
The skill documents and encourages network access to a local HTTP service but does not declare any explicit tool scope or permissions boundaries. This creates a governance gap: an agent may gain undeclared network capability, making review, policy enforcement, and user consent weaker for data exfiltration or unintended internal network access.
The manifest description and the entire skill documentation are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language policy issue because it effectively forces a locale/language without opt-in.
The skill sends user-supplied URLs and potentially retrieved content to an HTTP endpoint on a private network address. Because the service uses plain HTTP and targets an internal IP, it increases the risk of unencrypted data exposure, SSRF-like access to internal resources through the local crawler, and unintended transmission of sensitive browsing targets within a trusted network context.
curl -X POST "http://192.168.1.2:3002/v1/scrape" \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com", "formats": ["markdown"]}'
The file's natural-language interface is entirely in Chinese, including the module docstring, function docstring, error messages, and CLI usage text. This imposes a specific language on users without opt-in or any documented region-specific justification, which matches the locale-policy violation criteria.
No suspicious patterns detected.