Skip to content
Report library
Purpose / Data analysis

Firecrawl Company Directories Skill Security Audit

What the author says it does (original text)

Extract structured company lists from directories with Firecrawl. Use for scraping YC, Crunchbase, Product Hunt, G2, startup directories, category directories, or custom company databases into JSON, CSV, CRM-ready lists, or research tables.

Independent security check

Low-risk issues found

Files checked
1
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Low risk

Directory requests and scraped content are processed by a hosted third party

Source references: 3
What we found

The Skill requires an API key for hosted Firecrawl requests and directs the agent to use Firecrawl browser or scraping functions. The target URL, filters, and retrieved page content may therefore be sent to Firecrawl.

Why this matters

If the target is private, authenticated, or commercially sensitive, a third party may process that content; requests also consume quota on the supplied key. No instruction to upload local files or steal the key is visible.

The Skill requires an API key for hosted Firecrawl requests and directs the agent to process directories with Firecrawl's browser or scrape/map features. When those features are used, directory addresses, query/filter actions, and page content may therefore be handled by the third-party Firecrawl service. If a directory or its filters contain non-public information, the user can ask the author to disclose the exact fields sent, retention terms, and privacy policy, and restrict use to public directories.

SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
Show 2 other places
SKILL.md:22In the instructionsOpen original file
Infer the directory, filters, result count, and output format from context. If the source is clear, proceed immediately.Ask at most 1-3 concise questions only if blocked, such as the directory URL/name, required filters, or target result count.
SKILL.md:28In the instructionsOpen original file
Use Firecrawl browser when the directory needs filters, pagination, infinite scroll, or profile clicks. Use scrape/map when listings are public and static.Suggested sources include YC companies, Crunchbase, Product Hunt, G2 categories, or any custom directory URL.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

6 instruction sections

The Skill uses Firecrawl to turn company directories into structured lists and requires an API key for the hosted service.

View source
SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
SKILL.md:16In the instructionsOpen original file
# Firecrawl Company DirectoriesUse this to turn startup or company directories into structured lists.

It selects browser interaction or static scraping based on the page and may apply filters, paginate, scroll, and open company profiles.

View source
SKILL.md:28In the instructionsOpen original file
Use Firecrawl browser when the directory needs filters, pagination, infinite scroll, or profile clicks. Use scrape/map when listings are public and static.Suggested sources include YC companies, Crunchbase, Product Hunt, G2 categories, or any custom directory URL.

Exports are limited to visible company information, with unavailable fields left blank rather than inferred.

View source
SKILL.md:34In the instructionsOpen original file
Capture fields that are visible:- name- description- industry/category- stage/founded/location/team size/funding when visible- tags- directory profile URL- company website URLLeave unavailable fields blank. Do not infer.

Quality requirements include deduplication, pagination tracking, and noting rate limits, login walls, or CAPTCHA blocks; the Skill does not instruct bypassing them.

View source
SKILL.md:72In the instructionsOpen original file
## Quality Bar- Deduplicate companies.- Track pagination progress.- Note rate limits, login walls, or CAPTCHA blocks.
Start here · InstructionsSKILL.md
firecrawl-company-directories
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Connect to websites
SKILL.md:8In the instructionsOpen original file
  version: "0.1.0"  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflows
SKILL.md:9In the instructionsOpen original file
  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflowsinputs:
SKILL.md:12In the instructionsOpen original file
  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true
Read keys or account settings
SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.
Lines read
77
File checksum (to compare versions)
46ed65cf82ffde3d0a06c6bccb4b54f6da38b0a92963e872fe4a6e959a21f786