Skip to content
Report library
Purpose / Other

Firecrawl Lead Research Skill Security Audit

What the author says it does (original text)

Produce pre-meeting lead intelligence briefs with Firecrawl. Use when the user needs company research, person research, recent news, talking points, pain points, or outreach preparation before a sales call, partnership meeting, investor conversation, or customer interview.

Independent security check

Security risks found

Files checked
1
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Meeting targets may be disclosed to a hosted search service without confirmation

Source references: 4
What we found

The instructions say to infer the company, person, and meeting context and proceed immediately when the company seems clear, then collect information through Firecrawl's hosted search and scraping service. Research queries may therefore reveal the target company, person's name, or meeting purpose to a third party without a separate confirmation.

Why this matters

The third-party service may receive queries and usage metadata concerning confidential sales leads, partnership discussions, investment diligence, or customer interviews. The supplied file does not state how that information is logged, retained, or reused.

The skill says to begin without reconfirmation when the company is clear and to use hosted Firecrawl search and scraping. Completing company/person research would ordinarily send the target name, URL, or related queries to that third party, so disclosure of the research target is a plausible risk. The source does not explicitly say the meeting context is sent to Firecrawl. Users can ask what fields are submitted or logged and restrict use to confirmed targets and public, non-sensitive information.

SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
Show 3 other places
SKILL.md:22In the instructionsOpen original file
Infer the company, person, meeting context, and desired brief depth from context. If the company is clear, proceed immediately.Ask at most 1-3 concise questions only if blocked, such as the company/person to research or the meeting context.
SKILL.md:26In the instructionsOpen original file
## Firecrawl Collection PlanUse Firecrawl search and scrape to gather:
SKILL.md:28In the instructionsOpen original file
Use Firecrawl search and scrape to gather:- company website, about, product, pricing, careers, team, and customer pages- recent news, funding, launches, hiring, partnerships, and press- public person profiles, talks, posts, interviews, and role/background- relevant industry context and likely business challenges
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

5 instruction sections

The Skill produces pre-meeting lead briefs for sales, partnership, investor, or customer conversations, covering company details, recent activity, key people, talking points, hypothesized pain points, and outreach suggestions.

View source
SKILL.md:3In the instructionsOpen original file
name: firecrawl-lead-researchdescription: Produce pre-meeting lead intelligence briefs with Firecrawl. Use when the user needs company research, person research, recent news, talking points, pain points, or outreach preparation before a sales call, partnership meeting, investor conversation, or customer interview.license: ISC
SKILL.md:51In the instructionsOpen original file
## Company Overview[What they do, stage/size signals, products, customers]## Recent Activity[News, launches, funding, hiring, partnerships]## Key People[Relevant people and public background]## Talking Points[5-7 specific conversation starters]## Likely Pain Points[Evidence-backed hypotheses]## Outreach Angle[Suggested positioning or next step]

It uses Firecrawl search and scraping to collect company-site material, news, public-person information, and industry context, and requires claims to be returned with source URLs.

View source
SKILL.md:28In the instructionsOpen original file
Use Firecrawl search and scrape to gather:- company website, about, product, pricing, careers, team, and customer pages- recent news, funding, launches, hiring, partnerships, and press- public person profiles, talks, posts, interviews, and role/background- relevant industry context and likely business challenges
SKILL.md:44In the instructionsOpen original file
Each researcher should return source URLs and only evidence-backed claims.

The Skill requires a Firecrawl API key for requests to Firecrawl's hosted service.

View source
SKILL.md:10In the instructionsOpen original file
  source: https://github.com/firecrawl/firecrawl-workflowsinputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true---
Start here · InstructionsSKILL.md
firecrawl-lead-research
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Connect to websites
SKILL.md:8In the instructionsOpen original file
  version: "0.1.0"  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflows
SKILL.md:9In the instructionsOpen original file
  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflowsinputs:
SKILL.md:12In the instructionsOpen original file
  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.    required: true
Read keys or account settings
SKILL.md:11In the instructionsOpen original file
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl requests.
Lines read
84
File checksum (to compare versions)
68a785e1d73da4b8777ed841dfc920b5663a0d00694aaa1f14488bff15726406