firecrawl / firecrawl/firecrawl-mcp-server

Free MCP security scan report for firecrawl-mcp

Open
#199 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
7.5k
Forks
884
Avg merge
1d 11h
Merged PRs (30d)
14

Description

# MCP Security Scan Report: firecrawl-mcp

**Scanned by:** AgentScore KYA Scanner (https://agentscores.xyz)
**Date:** 2026-03-30
**Package:** firecrawl-mcp@3.11.0
**Repository:** git+https://github.com/firecrawl/firecrawl-mcp-server.git
**Licence:** MIT
**Runtime dependencies:** 5

---

## Risk: LOW (Score: 100/100)

No security issues found. This package passed all checks.

---

## Dependency Chain Scan

Scanned 5 runtime dependencies. 0 flagged, 5 clean.

### Clean Dependencies

@mendable/firecrawl-js@4.18.0, dotenv@17.3.1, firecrawl-fastmcp@1.0.4, typescript@6.0.2, zod@4.3.6

---

## What We Check

- Install scripts (postinstall/preinstall hooks with network calls or code execution)
- Prompt injection patterns in metadata (15 patterns targeting AI agent manipulation)
- Suspicious URLs (sketchy TLDs, ngrok, webhook.site, raw public IPs)
- Dependency count (attack surface indicator)
- Metadata completeness (repository, licence, description)

This is a static metadata scan. It does not execute code, analyse runtime behaviour, or claim exploit detection. Full methodology: https://agentscores.xyz/docs

---

## Next Steps

This report is free. If you found it useful, we offer:

- **Continuous monitoring**: Get alerted when your package or its dependencies change risk level
- **Full security review**: Deeper analysis of your MCP server implementation, tool definitions, and permission model
- **Hardening support**: Practical fixes for any issues found

Scan any MCP package yourself: https://agentscores.xyz
Questions or feedback: https://agentscores.xyz/contact

---
*Generated by AgentScore KYA Scanner v1.0 on 2026-03-30. AgentScore is building the MCP security dataset.*

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.