Internal URLs or URLs containing sensitive parameters may be sent to hosted Firecrawl
Source references: 3The API key is described as being for “hosted Firecrawl requests,” while source URLs are mapped and scraped. Thus, supplied URLs and accessible content may be processed by a third party, without a required check that the source is public and non-sensitive.
Internal hostnames, unpublished documents, tokens in query strings, or restricted page content could be exposed to the provider and become subject to its logging, retention, and access policies.
The Skill explicitly requires a key for hosted Firecrawl requests and directs Firecrawl to map and scrape sources, so URLs supplied to the workflow would at least be sent as part of hosted requests, with fetched results processed by that service. “Internal or sensitive URLs” is only a conditional scenario: the source does not show intranet access or bypass of access controls. If URLs, query parameters, or page contents are sensitive, third-party processing creates a disclosure risk. Users can ask about retention and allow only public, sanitized URLs.
inputs: - name: FIRECRAWL_API_KEY description: Firecrawl API key for hosted Firecrawl requests. required: true---Show 2 other places
Use Firecrawl map for documentation sites, search for topic-based corpora, scrape pages into markdown, and preserve code examples and tables.Infer the source, goal, depth, and output location from context. If the source and goal are clear, proceed immediately.Ask at most 1-3 concise questions only if blocked, such as the source URL/topic, whether the output is reference/RAG/training/docs, or training format if training is requested.