Back to skill

Security audit

Firecrawl CLI

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Firecrawl CLI guide, but users should treat it as a third-party cloud scraping tool and handle API keys carefully.

Install this only if you intend to use Firecrawl for web scraping or cloud browser automation. Prefer browser login or a secret manager over pasting API keys into commands, consider pinning or reviewing the npm package before global installation, avoid sensitive internal or authenticated pages unless approved, and close cloud browser sessions or avoid reusable profiles when they could retain private state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Global npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 11
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

bash
npm install -g firecrawl-cli

Technical Analysis

The skill instructs users or agents to install firecrawl-cli from the npm registry without specifying an exact version or validating an integrity hash. Consequently, the package content installed at execution time may differ from the version reviewed during this audit.

npm packages may execute lifecycle scripts during installation. Because the command installs the package globally, such scripts execute with the installing user's privileges and can affect globally available tooling. The project provides no lockfile, package integrity value, vendored source, or reviewed version constraint that would make the dependency reproducible.

This finding does not establish that the current firecrawl-cli package is malicious. The vulnerability is the unsafe, non-reproducible dependency installation pattern and its exposure to package-registry or maintainer compromise.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, or its publishing pipeline.
  2. The attacker publishes a malicious or backdoored version under the existing package name.
  3. A user or agent follows the documented unpinned installation command.
  4. npm downloads the current package version rather than a previously reviewed version.
  5. Malicious package code or an installation lifecycle script executes with the installing user's privileges.
  6. The compromised globally installed CLI can subsequently intercept credentials, alter command results, or execute additional code whenever invoked.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account running npm. Potential effects include theft of environment variables and Firecrawl credentials, modification of u ...[truncated 432 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin firecrawl-cli to an exact, reviewed version rather than installing the latest available release.
  • Record and verify the expected package integrity hash.
  • Prefer a project-local dependency over a global installation to reduce system-wide impact.
  • Commit a lockfile and use a reproducible installation mechanism such as npm ci.
  • Disable npm lifecycle scripts during installation when they are not required, for example by using --ignore-scripts.
  • If lifecycle scripts are necessary, review them and the package's transitive dependencies before installation.
  • Establish a controlled process for reviewing and updating the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
references/commands.md:5
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: references/commands.md, line 5
Vulnerability Type: Sensitive credential supplied as a command-line argument
Risk Level: Medium

bash
firecrawl login --api-key fc-YOUR-KEY

Technical Analysis

The documented authentication command encourages users to replace the placeholder with a real Firecrawl API key on the command line. Command-line secrets can be retained in shell history, terminal session logs, command auditing systems, support diagnostics, or process metadata. On systems where process arguments are visible to other users or monitoring tools, the key may also be observable while the command is running.

Although the example contains only a placeholder and the repository does not contain a real credential, following the documented pattern with a production key creates a credential-disclosure risk.

Attack Path

  1. A user replaces fc-YOUR-KEY with a valid Firecrawl API key and executes the documented command.
  2. The shell records the complete command in its history, or a local process-monitoring or audit facility captures the process arguments.
  3. Another local user, support operator, malicious process, backup reader, or log consumer obtains access to that retained information.
  4. The attacker extracts the API key from the recorded command.
  5. The attacker submits requests to Firecrawl using the stolen credential until the key is revoked or expires.

Impact Assessment

A stolen key may permit unauthorized use of the associated Firecrawl account, including consumption of account credits and invocation of scraping, crawling, search, browser, or agent capabilities allowed by the credential. It may also expose account-associated job information if the service and credential permissions permit such access.

This issue does not directly grant local privilege escalation. Its scope is bounded by the permissions, quotas, and resources available to the comprom ...[truncated 13 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove examples that place API keys directly in command-line arguments.
  • Prefer an interactive authentication flow that reads secrets through a hidden prompt.
  • Where non-interactive authentication is required, inject the key through a secrets manager or a protected runtime environment rather than a literal shell command.
  • Warn users not to place credentials in shell history, scripts, screenshots, issue reports, or terminal logs.
  • Ensure any credential storage file is created with restrictive permissions and excluded from version control.
  • Recommend short-lived, least-privilege credentials where supported.
  • Document key rotation and revocation steps for users who may already have exposed a key through command history.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly promotes scraping, search, browser automation, and agent-driven queries through a third-party cloud-backed CLI, but it does not warn users that visited URLs, prompts, and scraped page contents may be transmitted to Firecrawl infrastructure. In a security-sensitive agent environment, this can lead to unintended disclosure of internal URLs, proprietary content, or sensitive prompts when operators assume the tool is purely local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation tells users to export an API key directly in the shell but gives no guidance about protecting the credential from shell history, logs, screenshots, or accidental sharing in transcripts. While this is common documentation shorthand, agent workflows often capture terminal output and command history, increasing the chance of credential exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.