Firecrawl Scrape Cn

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Chinese guide for using Firecrawl to fetch user-provided webpages into Markdown.

Install this if you want an agent to use Firecrawl for URLs you provide. Prefer a verified or pinned Firecrawl CLI over ad hoc `npx` execution, and avoid scraping private or authenticated pages unless you intend that content to be processed and saved locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is overly broad and includes common phrases like “抓取”, “抓网页”, “获取页面”, and “读取网页”, which can match many ordinary user requests beyond the intended narrow skill scope. This can cause unintended activation of a network-capable scraping tool, increasing the chance of surprise external requests, privacy issues, or tool misuse in contexts where the user did not clearly consent to web access.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal