{
  "format_version": "0.2.0",
  "report_id": "8b2cf09f-1461-499e-a6cd-7b469aab5bb9",
  "generated_at": "2026-08-11T06:17:28.665Z",
  "subject": {
    "server_name": "io.github.firecrawl/firecrawl-mcp-server",
    "artifact": {
      "ecosystem": "npm",
      "package": "firecrawl-mcp",
      "version": "3.23.9",
      "sha256": "e04a382e5540f277c57584dcb44409bed8845ac0d98cd37c73fc58fc69ca8d18",
      "download_url": "https://registry.npmjs.org/firecrawl-mcp/-/firecrawl-mcp-3.23.9.tgz",
      "registry_metadata_url": "https://registry.npmjs.org/firecrawl-mcp/3.23.9",
      "acquired_at": "2026-08-11T06:17:28.665Z",
      "registry_metadata_sha256": "4cdab581f5bf7408bc6c4a074a33bc7a958d2d1ba9a5ac0b00de088dd067b8f3",
      "integrity_claim": "sha512-vDzZWL9opg9m9vuV4EFMQcC+bp4dxdRNE77OPj5BTJU/QpQmxQs/CZj917Js3tGub+gpPnMrmYoOq/mctU07Fw==",
      "integrity_verified": true
    }
  },
  "analysis": {
    "engine": {
      "name": "sentinel",
      "version": "0.2.0",
      "build_sha256": "035867556006016143616283693ccfb76acfbfbca4b02bca71d729b7b1fbe2cf"
    },
    "protocol_profile": {
      "id": "mcp-2026-07-28",
      "specification_revision": "2026-07-28",
      "local_retrieval_date": "2026-08-01",
      "discovery_status": "not_run"
    },
    "authorization_profiles": [
      {
        "id": "none",
        "credential_present": false,
        "description": "No credentials were supplied."
      }
    ],
    "rule_pack": {
      "version": "0.1.0",
      "sha256": "302d85219dda34199bd2402fcc94ba34233152fe996a128e0b332ac3efef24b3"
    },
    "semantic_analysis": []
  },
  "observations": [
    {
      "id": "observation:package-metadata",
      "kind": "artifact_metadata",
      "coverage": "declared",
      "evidence": [
        {
          "sha256": "6656877a7bc2f8c0842f2291b73dc0b3226404cbe316672a160f6f5ed32b4c4a",
          "artifact_path": "package/package.json",
          "capture_kind": "artifact_file"
        }
      ],
      "data": {
        "name": "firecrawl-mcp",
        "version": "3.23.9",
        "mcpName": "io.github.firecrawl/firecrawl-mcp-server",
        "description": "MCP server for Firecrawl — search, scrape, and interact with the web. Supports both cloud and self-hosted instances. Features include web search, scraping, page interaction, batch processing, and LLM-powered content analysis.",
        "bin": {
          "firecrawl-mcp": "dist/index.js"
        },
        "scripts": {
          "build": "rm -rf dist && tsup && node -e \"require('fs').chmodSync('dist/index.js', '755')\"",
          "test": "npm run build && node --test tests/*.test.mjs",
          "start": "node dist/index.js",
          "start:cloud": "CLOUD_SERVICE=true node dist/index.js",
          "lint": "eslint src/**/*.ts",
          "lint:fix": "eslint src/**/*.ts --fix",
          "format": "prettier --write .",
          "publish-prod": "npm run build && npm publish",
          "publish-beta": "npm run build && npm publish --tag beta"
        },
        "engines": {
          "node": ">=22.0.0"
        }
      }
    },
    {
      "id": "observation:file-inventory",
      "kind": "file",
      "coverage": "declared",
      "evidence": [
        {
          "sha256": "e04a382e5540f277c57584dcb44409bed8845ac0d98cd37c73fc58fc69ca8d18",
          "capture_kind": "artifact_file"
        }
      ],
      "data": {
        "entry_count": 5,
        "regular_file_bytes": 164673,
        "entries": [
          {
            "path": "package/dist/index.js",
            "type": "file",
            "size": 126200,
            "sha256": "e6191527d4c6a047e9f3cb895e726f826e97028de80e31d021dc024bd26dd46a"
          },
          {
            "path": "package/dist/www-authenticate.js",
            "type": "file",
            "size": 175,
            "sha256": "e84a9ee0a8773281182ef9427daa9d4f9444419cf2b2efa3ba5fcf5306d3d2d2"
          },
          {
            "path": "package/LICENSE",
            "type": "file",
            "size": 1065,
            "sha256": "9c12811442b47e27f690be7cf0252f6bf93ddee18476f13e0fc6b4badb09c22c"
          },
          {
            "path": "package/package.json",
            "type": "file",
            "size": 1876,
            "sha256": "6656877a7bc2f8c0842f2291b73dc0b3226404cbe316672a160f6f5ed32b4c4a"
          },
          {
            "path": "package/README.md",
            "type": "file",
            "size": 35357,
            "sha256": "163f29338d359dc3c23e0800e9eea43b415390ff1b9708662e52cfd59ae43466"
          }
        ]
      }
    },
    {
      "id": "observation:registry-metadata",
      "kind": "artifact_metadata",
      "coverage": "declared",
      "evidence": [
        {
          "sha256": "4cdab581f5bf7408bc6c4a074a33bc7a958d2d1ba9a5ac0b00de088dd067b8f3",
          "capture_kind": "registry_metadata"
        }
      ],
      "data": {
        "metadata_url": "https://registry.npmjs.org/firecrawl-mcp/3.23.9",
        "requested_package": "firecrawl-mcp",
        "requested_version": "3.23.9",
        "tarball_url": "https://registry.npmjs.org/firecrawl-mcp/-/firecrawl-mcp-3.23.9.tgz",
        "integrity_claim": "sha512-vDzZWL9opg9m9vuV4EFMQcC+bp4dxdRNE77OPj5BTJU/QpQmxQs/CZj917Js3tGub+gpPnMrmYoOq/mctU07Fw==",
        "integrity_verified": true
      }
    },
    {
      "id": "observation:runtime-dependencies",
      "kind": "dependency",
      "coverage": "declared",
      "evidence": [
        {
          "sha256": "6656877a7bc2f8c0842f2291b73dc0b3226404cbe316672a160f6f5ed32b4c4a",
          "artifact_path": "package/package.json",
          "capture_kind": "artifact_file"
        }
      ],
      "data": {
        "dependencies": {
          "@mendable/firecrawl-js": "4.25.2",
          "dotenv": "^17.2.2",
          "fastmcp": "4.3.2",
          "zod": "^4.1.5"
        }
      }
    },
    {
      "id": "observation:network-api-dec00c44f02241f1",
      "kind": "code_indicator",
      "coverage": "inferred",
      "evidence": [
        {
          "sha256": "e6191527d4c6a047e9f3cb895e726f826e97028de80e31d021dc024bd26dd46a",
          "artifact_path": "package/dist/index.js",
          "capture_kind": "artifact_file",
          "byte_range": [
            6479,
            6485
          ]
        }
      ],
      "data": {
        "indicator": "network-api",
        "description": "Source references a network API."
      }
    },
    {
      "id": "observation:filesystem-api-449408c50e298c46",
      "kind": "code_indicator",
      "coverage": "inferred",
      "evidence": [
        {
          "sha256": "e6191527d4c6a047e9f3cb895e726f826e97028de80e31d021dc024bd26dd46a",
          "artifact_path": "package/dist/index.js",
          "capture_kind": "artifact_file",
          "byte_range": [
            120672,
            120681
          ]
        }
      ],
      "data": {
        "indicator": "filesystem-api",
        "description": "Source references a filesystem API."
      }
    },
    {
      "id": "observation:static-tool-inventory",
      "kind": "protocol_inventory",
      "coverage": "inferred",
      "evidence": [
        {
          "sha256": "e04a382e5540f277c57584dcb44409bed8845ac0d98cd37c73fc58fc69ca8d18",
          "capture_kind": "artifact_file"
        }
      ],
      "data": {
        "extraction": "static_source_analysis",
        "complete": false,
        "incompleteness": [
          "no_recognized_registration_pattern"
        ],
        "scanned_files": [
          "package/dist/index.js",
          "package/dist/www-authenticate.js"
        ],
        "tools": []
      }
    }
  ],
  "findings": [],
  "limitations": [
    {
      "code": "protocol_discovery_not_run",
      "summary": "M1 performs static artifact inspection only; no MCP protocol session was opened."
    },
    {
      "code": "tool_calls_not_performed",
      "summary": "No tools were invoked."
    },
    {
      "code": "semantic_analysis_not_run",
      "summary": "No semantic model analysis was run."
    },
    {
      "code": "static_tool_extraction_incomplete",
      "summary": "The declared tool surface could not be fully resolved from source (no_recognized_registration_pattern). Treat the inventory as a lower bound, not a complete list."
    }
  ]
}