mediumfirecrawl_parse
Arbitrary local filesystem read via filePath
The tool accepts a `filePath` parameter that is read directly from the server's local filesystem ('Local MCP reads filePath from the server filesystem'). There is no indication of path restriction, allowlisting, or sandboxing. If an attacker can influence the path passed to this tool (e.g., via a prompt injection from scraped web content, or by tricking the agent), it could be used to read sensitive local files (credentials, SSH keys, config files with secrets) and return their contents as 'parsed document content'. This capability is broader than the tool's stated purpose of parsing user-supplied documents and should be constrained to explicitly user-approved paths or a restricted directory.
lowfirecrawl_scrape
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowfirecrawl_search
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.