{"data":{"skill":{"slug":"firecrawl-firecrawl-agent","name":"firecrawl-agent","icon":"📦","repo":"https://github.com/firecrawl/cli/tree/main/skills/firecrawl-agent/","status":"approved","author":"firecrawl","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"8603a59f-07e5-4f96-b601-081fa7dbf538","skill_id":"7df8036c-3719-4df8-857f-027108482056","version":2,"content_hash":"61e958432b3893f4bc718fa0717f50a9","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static findings for markdown backticks, relative documentation links, and weak cryptography are false positives. The real risk is legitimate but elevated: the skill grants wildcard Firecrawl CLI execution, performs network extraction, and supports file output paths.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":7,"line_start":6},{"file":"SKILL.md","line_end":30,"line_start":24}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":30,"line_start":24}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":30,"line_start":24},{"file":"SKILL.md","line_end":44,"line_start":40}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Wildcard Firecrawl CLI Execution","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":7,"line_start":6}],"confidence":0.86,"description":"The allowed-tools block permits Bash(firecrawl *) and Bash(npx firecrawl *). This is needed for the skill, but wildcard command arguments increase impact if prompts or parameters are abused.","confidence_reasoning":"The Bash allowlist is explicit and uses wildcard arguments. The intent appears legitimate because all examples use the Firecrawl CLI for the documented extraction workflow."},{"title":"External Network Extraction By Design","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":30,"line_start":24}],"confidence":0.8,"description":"The skill instructs the agent to navigate websites and run Firecrawl Agent commands. User goals, URLs, schemas, and extracted page data may be processed through an external service.","confidence_reasoning":"The documented purpose is autonomous website extraction. This is not malicious, but it creates clear privacy and compliance considerations for target URLs and extracted data."}],"low_findings":[{"title":"Output And Schema File Path Handling","verdict":"NEEDS_REVIEW","locations":[{"file":"SKILL.md","line_end":30,"line_start":24},{"file":"SKILL.md","line_end":44,"line_start":40}],"confidence":0.67,"description":"The documented CLI options allow schema files and output paths. These are normal Firecrawl features, but users should avoid sensitive paths and review generated files before sharing.","confidence_reasoning":"The file path options are visible in examples and the options table. No evidence shows forced overwrite, unauthorized reads, or malicious path construction."},{"title":"Markdown Backtick Static Findings Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":44,"line_start":37},{"file":"SKILL.md","line_end":50,"line_start":48}],"confidence":0.97,"description":"The Ruby or shell backtick findings point to markdown code fences, inline option formatting, and tips. They do not show Ruby execution or shell substitution.","confidence_reasoning":"The cited lines are markdown syntax or inline code labels. They are documentation text, not executable Ruby or shell backtick expressions."},{"title":"Relative Documentation Links Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":57,"line_start":55}],"confidence":0.94,"description":"The path traversal findings are relative markdown links to neighboring Firecrawl skill documents. They are not file access logic and do not traverse user files at runtime.","confidence_reasoning":"The cited lines are documentation links under the See also section. No runtime filesystem operation or user-controlled path resolution is present."},{"title":"Weak Cryptography Findings Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":4,"line_start":3},{"file":"SKILL.md","line_end":35,"line_start":35}],"confidence":0.93,"description":"The cited lines do not contain cryptographic functions, hashes, ciphers, or password handling. No evidence found for weak cryptographic algorithm usage.","confidence_reasoning":"The cited locations are frontmatter description text and a markdown table header. There is no cryptographic implementation in the reviewed file."}],"dangerous_patterns":[{"title":"Wildcard Bash Tool Permission","locations":[{"file":"SKILL.md","line_end":7,"line_start":6}],"confidence":0.86,"description":"The skill grants Bash access for firecrawl and npx firecrawl commands with arbitrary trailing arguments. This should be treated as an external command execution permission.","confidence_reasoning":"The allowed-tools declaration directly shows wildcard Bash permissions for Firecrawl commands."},{"title":"CLI Output Path Argument","locations":[{"file":"SKILL.md","line_end":30,"line_start":24},{"file":"SKILL.md","line_end":44,"line_start":44}],"confidence":0.72,"description":"The skill documents output file path support through -o and --output. This can write generated extraction results to local paths chosen in the command.","confidence_reasoning":"The examples and option table show output path usage, but no malicious path is specified."}],"files_scanned":1,"total_lines":58,"audit_model":"codex","audited_at":"2026-06-30T01:19:47.78+00:00","created_at":"2026-06-30T01:34:38.315878+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":1,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}