Atlas / MCP servers / us / Crw

CrwBLOCK

mcp/us/crw

Fast, lightweight Firecrawl/Tavily alternative in Rust. Web scraper, crawler & search API with MCP server for AI agents. Drop-in Firecrawl-compatible API (/scrape, /crawl, /search). 2.3x faster than Tavily, 1.5x faster than Firecrawl in 1K-URL benchmarks. 6 MB RAM, single binary. Self-host or use ma

Verdict
BLOCK
Grade
F
Trust score
51 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
AGPL-3.0
Stars
1,084
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

fastCRW

Turn URLs into clean markdown or structured JSON with one engine for search, scrape, map, crawl, and extract.

Run it locally as a small Rust binary or use the managed API.

Get 1000 free credits → · Install · Docs

No credit card. Continue with GitHub.

One-command install

curl -fsSL https://fastcrw.com/install | sh

Runs local and free, no account needed. To use the Cloud, paste your key into the same command and it installs the binary, connects the key, and registers the MCP server with the AI coding tools you already have:

curl -fsSL https://fastcrw.com/install | CRW_API_KEY=crw_live_... sh
crw search "rust tutorials"

Claude Code, Cursor

Read from source at commit 60a6624c2752OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add crw:latest -- docker run -i --rm ghcr.io/fastcrw/crw:latest:None crw-mcp
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
CRWreadOpen-source Firecrawl alternative — self-hosted web scraper & crawler in Rust with MCP server for AI agents
04

Trust audit

BLOCKgrade F · trust 51/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (13 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/crw-browse/src/tools/goto.rs:365
"http://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/crw-core/src/url_safety.rs:248
|| host_lower == "metadata.google.internal"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/crw-core/src/url_safety.rs:362
assert!(validate_safe_url(&url("http://metadata.google.internal")).is_err());
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/crw-core/src/url_safety.rs:375
assert!(validate_safe_url(&url("http://169.254.169.254/latest/meta-data/")).is_err());
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
mcp/crw-mcp/bin/init.js:71
console.log(`\nAPI key set: ${apiKey.slice(0, 10)}... — export it for cloud mode:`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
mcp/crw-mcp/bin/init.js:72
console.log(`  export CRW_API_KEY=${apiKey}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
mcp/crw-mcp/bin/install.js:90
console.log(`\nMode: cloud — CRW_API_KEY ${apiKey.slice(0, 10)}... → ${apiUrl}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
config.default.toml:81
# base_url = "http://127.0.0.1:9377"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/crw-browse/src/tools/goto.rs:363
"http://127.0.0.1",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/crw-browse/src/tools/goto.rs:364
"http://10.0.0.1",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
crates/crw-mcp-proto/src/lib.rs:2993
let s = "👨👩👧👦".repeat(50); // family emoji, ZWJ sequences
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
blog/deep-research-agent-crw.md:353
api_key="crw_live_YOUR-FASTCRW-KEY",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
blog/google-adk-web-scraping.md:278
api_key="crw_live_YOUR-FASTCRW-KEY",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
blog/langgraph-web-scraping-agent.md:289
api_key="crw_live_YOUR-FASTCRW-KEY",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
blog/openai-agents-sdk-crw.md:281
api_key="crw_live_YOUR-FASTCRW-KEY",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mailmap
.mailmap
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
crates/crw-crawl/src/pdf.rs:1232
/// password-protected PDF, without needing to implement RC4/AES key
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
.github/workflows/google-indexing.yml:80
console.log(token.token);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/examples-test.yml:70
for f in ../../examples/crewai/*.py ../../examples/langchain/*.py; do
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/crw-cli/tests/journeys.rs:187
let installer = include_str!("../../../install.sh");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/crw-cli/tests/journeys.rs:202
let installer = include_str!("../../../install.sh");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/crw-core/src/config.rs:2643
let docker_cfg = concat!(env!("CARGO_MANIFEST_DIR"), "/../../config.docker");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/crw-extract/tests/adv_urls.rs:270
"../../up.png",

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 60a6624c2752full audit observations/trust-audit/mcp-server/us__crw.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2960a6624c2752BLOCKF51first audit
06

Questions

What is the Crw MCP server?

Fast, lightweight Firecrawl/Tavily alternative in Rust. Web scraper, crawler & search API with MCP server for AI agents. Drop-in Firecrawl-compatible API (/scrape, /crawl, /search). 2.3x faster than Tavily, 1.5x faster than Firecrawl in 1K-URL benchmarks. 6 MB RAM, single binary. Self-host or use ma

What tools does Crw expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Crw safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (51/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Crw need?

It reads CRW_API_KEY, FASTCRW_API_KEY, FIRECRAWL_API_KEY and JUDGE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Crw run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as crw-sdk at 0.36.0.

How current is this page?

The grade is for one exact copy of the source (60a6624c2752), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement