Skip to content
Report library
Purpose / Other

Firecrawl Competitive Intel Skill Security Audit

What the author says it does (original text)

Monitor competitor pricing, features, changelogs, dashboards, and product changes with Firecrawl. Use for recurring competitive intelligence, pricing tier extraction, feature change tracking, or structured competitor alerts.

Independent security check

Security risks found

Files checked
1
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Authenticated-page content may be shared with a hosted crawler and multiple research agents

Source references: 3
What we found

The workflow expressly permits authenticated dashboards, requires hosted Firecrawl requests, and may divide work among multiple researchers. Legitimate access does not automatically authorize disclosure of non-public page content to a third-party service or additional agents. The supplied material does not state which page data, session information, or credentials are transmitted or retained.

Why this matters

If the targets include paid accounts, partner portals, or other private dashboards, their content and source URLs may leave the user's current environment, widening exposure of commercially sensitive or account data.

The workflow requires an API key for hosted Firecrawl requests, permits authenticated dashboards when the user has legitimate access, and suggests splitting work among researchers when appropriate. Thus, if a user asks it to collect a private dashboard, its contents may pass through a third-party hosted service and additional research agents; permission to view a page does not itself authorize that disclosure. The source does not say session credentials are transmitted or describe retention, so credential exposure cannot be asserted. Users can ask the author to document data flow, credential isolation, and retention, and restrict runs to public pages or disable parallel agents.

SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
Show 2 other places
SKILL.md:28In the instructionsOpen original file
For each competitor, use Firecrawl scrape or browser as needed:- pricing pages, annual/monthly toggles, expanded feature tables- feature and product pages- changelogs, blogs, release notes, docs updates- authenticated dashboards only when the user has legitimate access
SKILL.md:35In the instructionsOpen original file
## Parallel WorkIf appropriate, use sub-agents or equivalent parallel task runners. A natural split is one competitor per researcher or one focus area per researcher.Each researcher should return pricing tiers, features, recent changes, source URLs, and confidence notes.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

6 instruction sections

This Skill is a documentation-only competitive-intelligence workflow. It directs an agent to use Firecrawl for competitor pricing, features, changelogs, and product pages and to retain visited source URLs. No scripts or installation steps are provided, so the exact request parameters, credential storage, and data handling cannot be verified.

View source
SKILL.md:28In the instructionsOpen original file
For each competitor, use Firecrawl scrape or browser as needed:- pricing pages, annual/monthly toggles, expanded feature tables- feature and product pages- changelogs, blogs, release notes, docs updates- authenticated dashboards only when the user has legitimate access
SKILL.md:74In the instructionsOpen original file
- Extract real plan names, limits, and dates when available.- Note contact-sales or gated details instead of guessing.- Preserve sources for diffing future runs.

The workflow requires an API key for hosted Firecrawl requests and permits parallel research split by competitor or focus area when appropriate.

View source
SKILL.md:10In the instructionsOpen original file
  source: https://github.com/firecrawl/firecrawl-workflowsinputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
SKILL.md:35In the instructionsOpen original file
## Parallel WorkIf appropriate, use sub-agents or equivalent parallel task runners. A natural split is one competitor per researcher or one focus area per researcher.Each researcher should return pricing tiers, features, recent changes, source URLs, and confidence notes.
Start here · InstructionsSKILL.md
firecrawl-competitive-intel
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Connect to websites
SKILL.md:8In the instructionsOpen original file
  version: "0.1.0"  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflows
SKILL.md:9In the instructionsOpen original file
  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflowsinputs:
SKILL.md:12In the instructionsOpen original file
  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true
Read keys or account settings
SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.
Lines read
77
File checksum (to compare versions)
730207f436ea7648e931058cdc84d244e2032cec5af12c802e2ba3d40ca46dc2