firecrawl — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited firecrawl (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use the Firecrawl CLI for live web search, URL extraction, site discovery, bulk crawls, browser-backed interaction, recurring monitors, offline site download, and local document parsing.
Use the installed CLI as command truth. Run firecrawl --help or firecrawl <command> --help before relying on version-sensitive flags. This skill is written for released firecrawl-cli 1.19.x behavior; do not teach or use unreleased GitHub-main flags unless local help confirms them.
Do not run firecrawl init, firecrawl setup skills, firecrawl setup mcp, firecrawl launch, or firecrawl make default from this skill unless the user explicitly asks for Firecrawl workstation maintenance. Those commands can modify installed skills, MCP config, or native web-provider defaults.
firecrawl --status.firecrawl <command> --help..firecrawl/ for reusable artifactswith scripts/firecrawl-cache-index.mjs; see references/cache-reuse.md.
.firecrawl/ with -o; do not stream large pagecontent into the agent context.
?, &, spaces, and brackets specially.material to Firecrawl unless the user explicitly permits external processing.
For setup/auth troubleshooting, read references/install-auth.md. For output safety, read references/output-security.md. For local drift checks, run scripts/firecrawl-doctor.mjs.
Read references/command-selection.md for the full decision tree. Default order:
search when no exact URL is known.scrape when a URL is known.map when a site is known but the exact page is not.crawl when many pages from a site/section are needed.monitor when the user needs ongoing change tracking.agent when the user wants structured data from complex sites and providesa schema, or schema-like target fields.
interact only after scrape when content requires clicks, forms, login,pagination, session state, or browser actions.
parse for local documents, not URLs.x download when the user wants a local offline site copy.research only for Firecrawl-native public arXiv or GitHub-historyresearch, and verify important claims against the underlying source.
doctor and feedback for diagnostics and concise upstream qualityfeedback.
--limit on search, map, crawl, agent, and x download..firecrawl artifacts before spending credits.map --search plus targeted scrape before broad crawls.crawl scoped with --include-paths, --exclude-paths, --max-depth,and --wait.
agent --max-credits and a schema for complex structured extraction.--redact-pii for contact pages, PDFs, user-generated pages, leadresearch, or anything likely to enter logs, shared artifacts, or vector stores.
the user explicitly needs that breadth.
Prefer these short chains before opening a detailed reference. Read references/recipes.md for schema, monitor JSON, jq, output-shape probes, profile, feedback, and download variants.
Search local cache before fetching a known URL:
FIRECRAWL_SKILL_DIR="${FIRECRAWL_SKILL_DIR:-$HOME/.agents/skills/firecrawl}"
node "$FIRECRAWL_SKILL_DIR/scripts/firecrawl-cache-index.mjs" find \
--url "https://example.com/page" \
--intent docs \
--jsonSearch with page content, inspect, then send feedback:
firecrawl search "query" --scrape --json -o .firecrawl/search-query.json
jq -r '.data.web[] | "\(.title): \(.url)"' .firecrawl/search-query.json
firecrawl search-feedback "$(jq -r '.id' .firecrawl/search-query.json)" --rating good --valuable-sources '[{"url":"https://example.com","reason":"Useful result"}]' --silent &Find a page on a known site, then scrape it:
firecrawl map "https://docs.example.com" --search "authentication" --json -o .firecrawl/map-auth.json
firecrawl scrape "https://docs.example.com/auth-page" -o .firecrawl/auth-page.mdScoped docs crawl:
firecrawl crawl "https://docs.example.com" --include-paths /docs --limit 50 --wait --pretty -o .firecrawl/crawl-docs.jsonScrape, interact, then stop:
firecrawl scrape "https://example.com" --profile example-site
firecrawl interact "Click the pricing tab and extract the visible plans"
firecrawl interact stopParse a local document:
firecrawl parse "./report.pdf" -o .firecrawl/report.mdOffline docs copy:
firecrawl x download "https://docs.example.com" --include-paths /docs --format markdown,links --limit 50 -yBasic recurring monitor:
firecrawl monitor create --name "Changelog" --schedule "every 30 minutes" --scrape-urls "https://example.com/changelog"Create .firecrawl/ first and use names that encode command plus subject:
.firecrawl/search-<slug>.json
.firecrawl/search-<slug>-scraped.json
.firecrawl/map-<site>-<topic>.json
.firecrawl/scrape-<site>-<page>.md
.firecrawl/scrape-<site>-<page>.json
.firecrawl/crawl-<site>-<scope>.json
.firecrawl/agent-<task>.json
.firecrawl/monitor-<name>.json
.firecrawl/parse-<document>.md
.firecrawl/schema-<purpose>.json
.firecrawl/index.jsonlBefore finalizing web-data work, preserve enough evidence to audit the answer:
printf 'Command: %s\nArtifact: %s\n' \
'firecrawl scrape "https://example.com/page" -o .firecrawl/scrape-example-page.md' \
'.firecrawl/scrape-example-page.md' \
> .firecrawl/scrape-example-page.evidence.txt
rg -n "pricing|limit|changed|released" .firecrawl/scrape-example-page.md \
>> .firecrawl/scrape-example-page.evidence.txtFinal answers should cite source URLs and local artifact paths when Firecrawl evidence materially supports the claim.
firecrawl --status; see references/install-auth.md.--limit, narrow scope, or stop and report.firecrawl doctor --json orfirecrawl doctor <job-id> --query "why did this run fail?".
--timeout, reduce scope, or use --wait-for for rendering.scrape with --wait-for; escalate tointeract only after a successful scrape.
scrape plus local diff instead.
scrape first and pass --profile or--scrape-id.
jq, and rerun with --jsonor --pretty.
firecrawl <command> --helpand update the skill later.
For Firecrawl SDK/API integration into an application, adding FIRECRAWL_API_KEY to a project, or choosing product endpoints, do not use this CLI skill as the implementation authority. Use the Firecrawl build skills if installed. For outcome deliverables such as research briefs, SEO audits, lead lists, QA reports, or design extraction, use the dedicated Firecrawl workflow skills if installed.
Use .firecrawl/ for fetched or parsed output unless the user explicitly wants inline content:
mkdir -p .firecrawl
firecrawl search "query" --json -o .firecrawl/search-query.json
firecrawl scrape "https://example.com/page" -o .firecrawl/example-page.mdInspect output incrementally:
wc -l .firecrawl/example-page.md
head -80 .firecrawl/example-page.md
rg -n "pricing|authentication" .firecrawl/example-page.mdSingle-format scrape/parse output is raw content. Multiple formats usually return JSON. When using search --scrape, do not re-scrape those result URLs unless the scraped payload is missing what the task needs.
For command-specific output shapes and resilient jq probes, open the matching reference file rather than a separate shape reference.
When maintaining this skill:
node scripts/firecrawl-doctor.mjs --json
node scripts/firecrawl-help-snapshot.mjs --output /tmp/firecrawl-help.jsonThe scripts are diagnostics only. They do not wrap Firecrawl operations and they do not install Firecrawl skills.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.