Back to skill

Security audit

Firecrawl

Security checks for vulnerabilities and agentic risk

Overview

This Firecrawl skill is a disclosed Maton/Firecrawl integration with broad but clearly described automation features and strong user-approval guardrails.

Install this only if you are comfortable using Maton as a gateway for Firecrawl and automation. Before approving actions, check the exact URL scope, credit impact, third-party processing, connection identity, and whether any trigger or destination would keep forwarding data after the immediate task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The Firecrawl skill includes a full HubSpot trigger reference that is unrelated to Firecrawl’s stated web crawling/search scope. Even though the text says it is shared platform reference material, embedding actionable cross-product event capabilities in this skill can confuse an agent into assuming the skill supports HubSpot-triggered automation, expanding effective behavior beyond the user’s expected trust boundary.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The file explicitly claims the shared reference does not widen scope, but it still provides concrete HubSpot event types, parameters, and payloads that an agent could operationalize. This mismatch is dangerous because declarative safety language does not prevent a model from using the documented capabilities, creating a prompt-scope confusion issue that may lead to unauthorized or unintended cross-app automation behavior.

Static analysis

No suspicious patterns detected.