Firecrawl Build Scrape

Security checks across malware telemetry and agentic risk

Overview

This is a small documentation-only Firecrawl scraping skill whose external API use is purpose-aligned, with no executable code or hidden persistence.

Install this only if you are comfortable sending target URLs and scraped page content to Firecrawl or your configured self-hosted Firecrawl endpoint. Avoid using it for private, authenticated, internal, secret-bearing, or regulated pages unless you have approved data-handling terms and a clear trust boundary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill requires a Firecrawl API key and instructs users to send URLs for scraping, but it does not warn that supplied URLs and resulting page content will be transmitted to an external Firecrawl service. This omission can cause developers to integrate the skill into workflows that process sensitive internal URLs, authenticated pages, or regulated data without obtaining consent or applying data-handling safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal