Atlas / MCP servers / firecrawl / firecrawl-mcp

firecrawl-mcpCAUTION

mcp/firecrawl/firecrawl-mcp-server

🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients.

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
7,565
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img src="https://raw.githubusercontent.com/firecrawl/firecrawl-mcp-server/main/img/fire.png" height="140"

A Model Context Protocol (MCP) server that brings Firecrawl to MCP-compatible AI agents — search, scrape, and interact with the live web for clean, agent-ready context.

Big thanks to @vrknetha, @knacklabs for the initial implementation!

Features

  • Search the web and get full page content
  • Search an index built for coding agents: GitHub issues, merged pull requests, READMEs, and docs
  • Scrape any URL into clean, structured data
  • Interact with pages — click, navigate, and operate
  • Deep research with autonomous agent
  • Check current and historical Firecrawl credit usage
  • Automatic retries and rate limiting
  • Cloud and self-hosted support
  • SSE support
Play around with our MCP Server on MCP.so's playground or on Klavis AI.

When to Use This Server

  • Use firecrawl_scrape when you have a known URL and want its content as markdown or as JSON matching a schema you supply.
  • Use firecrawl_map when you need to discover URLs on a site without fetching their content.
  • Use firecrawl_crawl when you need content from many pages under a site; set limit, includePaths/excludePaths, or maxDiscoveryDepth to bound it.
  • Use firecrawl_search when you're starting from a query rather than a URL and want ranked web results; add scrapeOptions if you also want page content fetched in the same call (the search-only endpoint never fetches content).
  • Use firecrawl_interact when a page needs a click, type, or navigate action before you can read it — pass a url for a fresh page or a scrapeId to continue on one you already scraped.
  • Use the firecrawl_monitor_* t
Read from source at commit ac61ac69b031OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add firecrawl-mcp --env FIRECRAWL_API_KEY=${FIRECRAWL_API_KEY} -- npx -y [email protected]
03

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (16)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/mcp-smoke.test.mjs:3043
api_key: 'fc-managed-parse-key',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/mcp-smoke.test.mjs:3672
api_key: 'fc-untrusted-purpose',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/mcp-smoke.test.mjs:4051
api_key: 'fc-managed-credit-usage',
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/openai/app-6a314a73f8ac819195b0d55e36b9c609/.app.json
.app.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/helpers/plugin-contract.mjs:8
'../../plugins/openai/app-6a314a73f8ac819195b0d55e36b9c609/',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/helpers/plugin-contract.mjs:13
new URL('../../plugins/claude/firecrawl-search/', import.meta.url)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/agent-hints.test.mjs:118
FIRECRAWL_API_URL: `http://127.0.0.1:${backendPort}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/agent-hints.test.mjs:120
FIRECRAWL_OAUTH_ISSUER: `http://127.0.0.1:${backendPort}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/helpers/exchange-api.mjs:49
const url = new URL(req.url ?? '/', 'http://127.0.0.1');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/helpers/exchange-api.mjs:195
url: `http://127.0.0.1:${server.address().port}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/helpers/exchange-mcp.mjs:32
const response = await fetch(`http://127.0.0.1:${port}/health`);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, fuse.js, hono, mcp-proxy, undici, uri-templates, xsschema
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:40
- `firecrawl_parse` now works on the remote hosted MCP server (`CLOUD_SERVICE`), not just local mode. Because the hosted server cannot read the caller's filesystem, hosted parse uses a two-call flow:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
img/fire.png
img/fire.png
Why it matters. 2726130 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:18
- Keyless recovery messages now link to the caller's own signup link, `https://firecrawl.dev/k/<token>` (a 12-character encrypted token), instead of `/app/api-keys`. The API issues the link (the `sign
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ac61ac69b031full audit observations/trust-audit/mcp-server/firecrawl__firecrawl-mcp-server.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ac61ac69b031CAUTIONB82first audit
05

Questions

What is the firecrawl-mcp MCP server?

🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients.

Is firecrawl-mcp safe to connect to an agent?

With care. The audit graded it B (82/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does firecrawl-mcp need?

It reads FIRECRAWL_API_KEY, FIRECRAWL_MCP_ACTION_LOG_SECRET, FIRECRAWL_MCP_SEARCH_OAUTH_ONLY, FIRECRAWL_OAUTH_INTROSPECT_CACHE_TTL_MS, FIRECRAWL_OAUTH_INTROSPECT_SECRET, FIRECRAWL_OAUTH_ISSUER, FIRECRAWL_OAUTH_TOKEN, KEYLESS_PROXY_SECRET, MCP_DELEGATED_CREDENTIAL_SECRET, MCP_OAUTH_ACCEPT_LEGACY_V2_MCP_AUD and OPENAI_APPS_CHALLENGE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does firecrawl-mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as firecrawl-mcp at 3.28.2.

How current is this page?

The grade is for one exact copy of the source (ac61ac69b031), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement