Back to plugin

Security audit

OpenClaw Firecrawl Plugin

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently adds Firecrawl-powered web search and page scraping, with expected external network use and credential handling.

Install only if you want OpenClaw to use Firecrawl for web search and page scraping. Expect requested queries, target URLs, and scraped page content to be sent to Firecrawl or your configured Firecrawl-compatible endpoint, and use the storeInCache setting carefully for sensitive pages.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/.setup/firecrawl-fetch-provider-Cq_h8okw.mjs:38
Evidence
const apiKey = [REDACTED])?.webSearch?.apiKey;