! Security: Review · 88 88/100 · grade B scanned 1mo ago
✓ no compromise signals 13 risk-surface · 7/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface , expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · high confidence (static)
Tools (1)
firecrawl_check_crawl_status
⚑ filesystem ⚑ shell ⚑ network ⚑ secrets
egress → smithery.ai., smithery.ai, www.knacklabs.ai, mcp.so, www.klavis.ai, mcp.firecrawl.dev, docs.firecrawl.dev, www.firecrawl.dev +12
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10 . Expand any flagged control for the exact findings — compromise reduces the score; expected /risk-surface do not, except a known CVE , which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠ LLM03 Supply Chain high Vulnerable/compromised dependencies, models or archives in the artifact.
• Dependency manifest — 11 npm dependencies declared · firecrawl-firecrawl-mcp-server-3eb1115/package.json risk surface
• Vulnerable dependencies — 16 known vulnerabilities in: axios@1.15.2, esbuild@0.27.7, follow-redirects@1.15.11, form-data@4.0.5, path-to-regexp@8.3.0, qs@6.14.0 (CWE-1395)known CVE · -12 pts
⚠ LLM05 Improper Output Handling high Code that pipes model/user output into shell, eval, SQL or paths unsafely.
• Suspicious code patterns — environment/secret exfiltration · firecrawl-firecrawl-mcp-server-3eb1115/src/index.ts (CWE-200)risk surface
• Suspicious code patterns — child_process exec · firecrawl-firecrawl-mcp-server-3eb1115/tests/mcp-smoke.test.mjs (CWE-78)risk surface
⚠ LLM06 Excessive Agency medium Over-broad tool/permission surface or unrestricted egress.
• External endpoints declared — 1 distinct host(s) · firecrawl-firecrawl-mcp-server-3eb1115/.github/workflows/publish.yml risk surface
• External endpoints declared — 2 distinct host(s) · firecrawl-firecrawl-mcp-server-3eb1115/Dockerfile risk surface
• Broad capability surface — 3 high-impact capability categories referenced — verify least-privilege · firecrawl-firecrawl-mcp-server-3eb1115/README.md (CWE-272)risk surface
• External endpoints declared — 17 distinct host(s) · firecrawl-firecrawl-mcp-server-3eb1115/README.md risk surface
• External endpoints declared — 3 distinct host(s) · firecrawl-firecrawl-mcp-server-3eb1115/docker/nginx.conf risk surface
• Broad capability surface — 4 high-impact capability categories referenced — verify least-privilege · firecrawl-firecrawl-mcp-server-3eb1115/pnpm-lock.yaml (CWE-272)risk surface
• External endpoints declared — 7 distinct host(s) · firecrawl-firecrawl-mcp-server-3eb1115/src/index.ts risk surface
⚠ LLM07 System Prompt Leakage medium Secrets, internal hosts or proprietary logic exposed in shipped prompts.
• Internal host / private infrastructure reference — shipped content references a private IP range or internal-only host · firecrawl-firecrawl-mcp-server-3eb1115/tests/mcp-smoke.test.mjs (CWE-200)risk surface
⚠ LLM10 Unbounded Consumption medium Unbounded loops/recursion causing DoS or runaway cost.
Enforced at runtime by the gateway (rate limits + spend caps + size caps); static check flags unbounded loops.
• Potentially unbounded loop — an infinite loop (while True / while(1) / for(;;)) may cause runaway consumption · firecrawl-firecrawl-mcp-server-3eb1115/src/index.ts (CWE-835)risk surface
§ LLM09 Misinformation Governance Artifacts designed to produce false/deceptive output.
Detectable only by runtime behavioral evaluation; addressed via responsible-use attestation.
✓ LLM01 Prompt Injection Passed
✓ LLM02 Sensitive Information Disclosure Passed
✓ LLM04 Data and Model Poisoning Passed Backdoors/poisoning in training data or serialized models.
Behavioral poisoning needs model execution; static check covers unsafe serialization + dataset skew only.
✓ LLM08 Vector and Embedding Weaknesses Passed PII or plaintext source leakage in embedding/vector exports.
Embedding inversion/poisoning is largely runtime; static check covers PII in vector exports.
OWASP Machine Learning Security Top 10
⚠ ML06 AI Supply Chain high Compromised PyPI/npm packages, typosquats, unsafe serialized models.
• Dependency manifest — 11 npm dependencies declared · firecrawl-firecrawl-mcp-server-3eb1115/package.json risk surface
• Vulnerable dependencies — 16 known vulnerabilities in: axios@1.15.2, esbuild@0.27.7, follow-redirects@1.15.11, form-data@4.0.5, path-to-regexp@8.3.0, qs@6.14.0 (CWE-1395)known CVE · -12 pts
⚠ ML09 Output Integrity high Middleware tampering with model outputs in transit.
Gateway enforces TLS + response integrity; static check flags output-rewriting code.
• Suspicious code patterns — environment/secret exfiltration · firecrawl-firecrawl-mcp-server-3eb1115/src/index.ts (CWE-200)risk surface
• Suspicious code patterns — child_process exec · firecrawl-firecrawl-mcp-server-3eb1115/tests/mcp-smoke.test.mjs (CWE-78)risk surface
§ ML01 Input Manipulation (Adversarial) Governance Models vulnerable to adversarial perturbations.
Requires runtime robustness evaluation; addressed via publisher robustness attestation.
§ ML03 Model Inversion Governance Training data reconstructable from a model's outputs.
Runtime/evaluation property; addressed via model-card data-provenance + DP attestation.
§ ML04 Membership Inference Governance Determining whether a record was in the training set.
Runtime/evaluation property; addressed via overfitting disclosure + DP attestation.
§ ML08 Model Skewing Governance Models trained on skewed data producing biased output.
Requires fairness evaluation; addressed via model-card bias/limitations disclosure.
✓ ML02 Data Poisoning Passed Poisoned training datasets with triggers or anomalous distributions.
Static check covers trigger phrasing, PII and label skew; full poisoning detection is runtime.
✓ ML05 Model Theft Passed Unlicensed re-distribution / license-incompatible derivatives.
Static check verifies license declaration; extraction throttling is runtime.
✓ ML07 Transfer Learning Attack Passed Backdoored base models / LoRA adapters propagating to derivatives.
Backdoor detection needs behavioral probing; static check covers unsafe serialization + provenance.
✓ ML10 Model Poisoning (Weights) Passed Tampered model weight files; integrity must be verifiable.
Static check enforces safe formats + records a content hash for downstream verification.
Other findings (8) · hygiene / uncategorized • Unrecognized file type — '.dockerignore' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/.dockerignore risk surface
• Unrecognized file type — '.gitignore' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/.gitignore risk surface
• Unrecognized file type — '.prettierrc' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/.prettierrc risk surface
• Unrecognized file type — '.?' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/Dockerfile risk surface
• Unrecognized file type — '.service' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/Dockerfile.service risk surface
• Unrecognized file type — '.conf' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/docker/nginx.conf risk surface
• Unrecognized file type — '.mjs' is not on the allowlist · firecrawl-firecrawl-mcp-server-3eb1115/tests/mcp-smoke.test.mjs risk surface
• Suspicious network references — raw IP URL (17 URLs) · firecrawl-firecrawl-mcp-server-3eb1115/tests/mcp-smoke.test.mjs risk surface
✔ verified source · pinned firecrawl-firecrawl-mcp-server-3eb1115
Check against a policy
The same gate an agent runs before installing (POST /api/v1/trust/firecrawl-mcp-server/check). Click a policy:
No shell/exec No unknown egress Grade B or better No secrets access No install hooks Strict (B+ · no shell · no egress)