Firecrawl Crawl

Security checks across malware telemetry and agentic risk

Overview

This appears to be a website extraction skill with a scope-control risk, but no evidence of hidden, destructive, or deceptive behavior.

Install only if you want an agent to crawl and extract website content. When using it, specify the exact domain/path, page limits, and concurrency or budget limits to avoid unnecessary crawling or credit use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description contains broad trigger phrases like "crawl", "get all the pages", "extract everything under /docs", and "bulk extract", which are common natural-language requests and can cause the skill to be invoked in situations where the user did not explicitly intend to use this tool. Because this skill performs large-scale website extraction and supports concurrent crawling, accidental invocation can lead to unnecessary external actions, excess credit consumption, or collection of more data than needed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal