Security Audit
firecrawl-scraper
github.com/sickn33/antigravity-awesome-skillsTrust Assessment
firecrawl-scraper received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Skill installation points to external, different repository.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit e36d6fd3). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Skill installation points to external, different repository The `SKILL.md` file for the `firecrawl-scraper` skill, hosted within the `sickn33/antigravity-awesome-skills` repository, instructs users to install the skill from `BenedictKing/firecrawl-scraper`. This directs users to an external GitHub repository/user, which differs from the repository currently hosting this documentation. This introduces a supply chain risk as the installed skill's provenance is different from the expected source, potentially leading to the installation of an unvetted or malicious package if the external repository is compromised or malicious. 1. If the skill is indeed hosted by `sickn33`, update the installation command to point to the correct repository (e.g., `npx skills add -g sickn33/antigravity-awesome-skills/skills/firecrawl-scraper` or similar, depending on the skill system's exact pathing). 2. If `sickn33` is merely documenting `BenedictKing`'s skill, clarify this relationship in the documentation and consider adding a disclaimer about third-party dependencies. 3. Ensure the `BenedictKing/firecrawl-scraper` repository is trustworthy and actively maintained if it's the intended source. | LLM | SKILL.md:16 |
Scan History
Embed Code
[](https://skillshield.io/report/cca9b16a611e8760)
Powered by SkillShield