firecrawl / firecrawl/firecrawl-mcp-server

Security scan results for firecrawl-mcp-server — MCPSafe AIVSS 62/100 (Grade D)

Open
#233 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
7.5k
Forks
884
Avg merge
1d 11h
Merged PRs (30d)
14

Description

Hi team 👋

I ran a free deep security scan of **mendableai/firecrawl-mcp-server** using [MCPSafe](https://mcpsafe.io) — a purpose-built scanner for MCP servers using a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

## Results: 62/100 · Grade D

| Severity | Count |
|----------|-------|
| 🔴 Critical | 0 |
| 🟠 High | 3 |
| 🟡 Medium | 25 |
| 🟢 Low | 0 |

**Summary:** 3 high + 25 medium findings — notable for a server that crawls arbitrary web content and is exposed to prompt injection via crawled pages

📋 **Full report with findings and evidence:** https://mcpsafe.io/registry/github/mendableai/firecrawl-mcp-server

---

## Add a security badge to your README

```markdown
[![MCPSafe](https://api.mcpsafe.io/badge/github/mendableai/firecrawl-mcp-server.svg)](https://mcpsafe.io/registry/github/mendableai/firecrawl-mcp-server)
```

This badge auto-updates whenever a new scan runs — great for showing users and enterprise customers your security posture at a glance.

---

Feel free to close this if you're already tracking these findings. Happy to answer any questions about specific findings.

— Truong BUI · [mcpsafe.io](https://mcpsafe.io)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.