Protected-site credentials and content may pass through hosted Firecrawl
Source references: 3The instructions permit requesting credentials for protected flows, direct the browser to operate forms and scrape page content, and state that the API key is for hosted Firecrawl requests. If those features run through the hosted service, login details, session-visible data, or scraped content may leave the user's environment.
Test-account passwords, session data, internal page content, customer information, or other non-public material could be exposed to a third party and become subject to its logging, retention, and access policies.
The Skill requires an API key for hosted Firecrawl requests, permits asking about credentials for protected flows, and calls for browser and scraping functions. However, the visible text does not say that login credentials are sent to Firecrawl, where the browser runs, how session data is handled, or whether scraped content leaves the user's environment. Third-party processing is possible, but the claimed data flow is not established. A user can ask for execution, logging, and retention details and restrict testing to non-sensitive test accounts.
This assessment concerns the code and conditions shown, not proof that harm has occurred.inputs: - name: FIRECRAWL_API_KEY description: Firecrawl API key for hosted Firecrawl requests. required: true---Show 2 other places
Ask at most 1-3 concise questions only if blocked, such as the URL, the focus area, or credentials/constraints for protected flows.Use Firecrawl map to discover pages. Use Firecrawl browser for interactions, forms, navigation, and responsive/manual checks when available. Use scrape for page content and link extraction.