firecrawl / firecrawl/firecrawl-mcp-server
Free MCP security scan report for firecrawl-mcp
- Dominant language
- JavaScript
- Stars
- 7.5k
- Forks
- 884
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 14
Description
# MCP Security Scan Report: firecrawl-mcp
**Scanned by:** AgentScore KYA Scanner (https://agentscores.xyz)
**Date:** 2026-03-30
**Package:** firecrawl-mcp@3.11.0
**Repository:** git+https://github.com/firecrawl/firecrawl-mcp-server.git
**Licence:** MIT
**Runtime dependencies:** 5
---
## Risk: LOW (Score: 100/100)
No security issues found. This package passed all checks.
---
## Dependency Chain Scan
Scanned 5 runtime dependencies. 0 flagged, 5 clean.
### Clean Dependencies
@mendable/firecrawl-js@4.18.0, dotenv@17.3.1, firecrawl-fastmcp@1.0.4, typescript@6.0.2, zod@4.3.6
---
## What We Check
- Install scripts (postinstall/preinstall hooks with network calls or code execution)
- Prompt injection patterns in metadata (15 patterns targeting AI agent manipulation)
- Suspicious URLs (sketchy TLDs, ngrok, webhook.site, raw public IPs)
- Dependency count (attack surface indicator)
- Metadata completeness (repository, licence, description)
This is a static metadata scan. It does not execute code, analyse runtime behaviour, or claim exploit detection. Full methodology: https://agentscores.xyz/docs
---
## Next Steps
This report is free. If you found it useful, we offer:
- **Continuous monitoring**: Get alerted when your package or its dependencies change risk level
- **Full security review**: Deeper analysis of your MCP server implementation, tool definitions, and permission model
- **Hardening support**: Practical fixes for any issues found
Scan any MCP package yourself: https://agentscores.xyz
Questions or feedback: https://agentscores.xyz/contact
---
*Generated by AgentScore KYA Scanner v1.0 on 2026-03-30. AgentScore is building the MCP security dataset.*
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.