跳转到正文
报告库
用途分类 / 文档处理

Firecrawl Research Papers Skill 安全审计

作者说它能做什么(原文)

Find and synthesize research papers, whitepapers, PDFs, technical reports, and academic sources with Firecrawl Research, using semantic paper search, related-paper expansion, and in-body verification over Firecrawl's paper index — largely biomedical and life-science literature from PubMed, bioRxiv, and medRxiv, plus arXiv preprints in CS, physics, and math. Use when the user wants a literature rev

第三方安全检查结论

发现安全风险

已检查文件
1
发现的风险
3
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

研究主题和查询内容会发送给托管的 Firecrawl 服务

原文依据:3 处
发现了什么

该 Skill 要求 Firecrawl API 密钥,并将托管服务作为论文发现和验证的主要路径。查询、论文标识、验证问题及被抓取的网址因此可能由第三方服务处理。

为什么需要注意

若研究主题包含未公开的产品计划、患者信息、法律事项或其他机密内容,这些内容可能离开用户的本地环境,并受 Firecrawl 的日志、保留和访问政策约束。现有文本没有说明数据保留或隐私边界。

该 Skill 明确要求 Firecrawl API 密钥,并把 Firecrawl 的托管工具作为论文发现与核验的主要路径。实际使用这些工具时,研究查询、论文 ID、正文核验问题或抓取 URL 会提交给 Firecrawl;这会向第三方披露研究兴趣及查询内容,但证据未表明会上传用户本地文件。用户可要求作者说明 Firecrawl 的数据保留、日志和训练政策,或限制敏感主题与可提交内容。

SKILL.md:10来自说明文档打开原文件
  source: https://github.com/firecrawl/firecrawl-workflowsinputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl Research, CLI, MCP, or equivalent tool requests.    required: true---
查看另外 2 个位置
SKILL.md:28来自说明文档打开原文件
Use Firecrawl Research through the CLI, MCP, or equivalent Firecrawl toolsurface as the primary path for paper discovery and verification. Fall back togeneral Firecrawl search and scrape for whitepapers, technical reports,research blogs, leaderboards, or facts outside the paper corpus.
SKILL.md:56来自说明文档打开原文件
  categories, source ids, and dates.- MCP: `firecrawl_research_read_paper(id, question)`  CLI: `firecrawl research read-paper <id> --question <question>`  Verify a specific claim or constraint inside one paper, such as method,  reported score, benchmark, affiliation, comparison, or limitation.- MCP: `firecrawl_search(query)` / `firecrawl_scrape(url)`  CLI: `firecrawl search <query>` / `firecrawl scrape <url>`  Use for web-only context: benchmark leaderboards, rankings, reports,  whitepapers, research blogs, and source pages outside the paper index.
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。发现 1 项风险
中风险

读取的论文和网页未被明确隔离为不可信内容

原文依据:2 处
发现了什么

该 Skill 指示代理读取论文正文并抓取外部网页,但没有要求忽略这些来源中面向代理的命令。恶意或被篡改的页面可能把提示注入伪装成论文内容。

为什么需要注意

如果代理把来源中的命令当作工作流指令,可能偏离研究任务、错误呈现结论,或在其权限允许时调用其他工具、泄露上下文数据。仅检索到恶意文本并不等于攻击已经成功。

这些是会读取论文正文及抓取外部网页的实时工作流指令,而文件没有给出将返回内容视为不可信数据、忽略其中操作命令或限制后续工具行为的防护。若论文或网页含有面向代理的恶意指令,代理可能误把它当作工作流命令;证据只支持这种潜在风险,不证明攻击已发生。用户可要求只提取引用文本、禁止来源内容触发工具或权限操作,并对外部内容做提示注入隔离。

SKILL.md:56来自说明文档打开原文件
  categories, source ids, and dates.- MCP: `firecrawl_research_read_paper(id, question)`  CLI: `firecrawl research read-paper <id> --question <question>`  Verify a specific claim or constraint inside one paper, such as method,  reported score, benchmark, affiliation, comparison, or limitation.- MCP: `firecrawl_search(query)` / `firecrawl_scrape(url)`  CLI: `firecrawl search <query>` / `firecrawl scrape <url>`  Use for web-only context: benchmark leaderboards, rankings, reports,  whitepapers, research blogs, and source pages outside the paper index.
查看另外 1 个位置
SKILL.md:88来自说明文档打开原文件
  read-paper to verify the property.- Superlatives and leaderboards: use general web search or scrape to find the  ranking, then map top entries back to papers with paper search.- Author, organization, venue, date, or methodology constraints: verify with  inspect-paper metadata or read-paper before keeping a candidate.
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 1 项风险
中风险

重复搜索和论文扩展可能产生未设上限的 API 用量

原文依据:5 处
发现了什么

工作流要求对部分问题使用多种查询表述、扩展多个种子并从新结果继续播种,同时建议不要止步于一个强结果。文本没有规定调用次数、结果数或费用上限。

为什么需要注意

在按请求或用量计费的 Firecrawl 账户上,宽泛主题、大目标数量或并行研究可能消耗更多配额并产生超出用户预期的费用。

该 Skill 明确要求在结果不足时改写查询,并对枚举类任务扩展多个种子、再从新论文继续播种;原则部分还要求不要停在一个结果。虽然每次搜索可指定 `k`,但流程没有总体调用次数、结果数、预算或停止条件,因此在按量计费的托管 API 上可能产生超出预期的费用。用户可在运行前要求设定最大调用数、每次 `k`、总论文数和费用上限。

SKILL.md:42来自说明文档打开原文件
- MCP: `firecrawl_research_search_papers(query, k?)`  CLI: `firecrawl research search-papers <query> [--k <number>]`  Semantic search over paper abstracts. Start here for most paper-finding  queries, and retry with alternate framing when results are thin or too  narrow.- MCP: `firecrawl_research_related_papers(seed_ids, intent, mode?, k?)`  CLI: `firecrawl research related-papers <seedIds...> --intent <intent> [--mode <similar|citers|references>] [--k <number>]`  Expand from strong seed papers into similar work, citing papers, or  references. Use this to find the relevant paper family, not just the first  matching result.- MCP: `firecrawl_research_inspect_paper(id)`
查看另外 4 个位置
SKILL.md:82来自说明文档打开原文件
  then expand with related papers and keep close neighbors.- Enumeration queries, such as papers that do a task or benchmark a method:  search multiple framings, expand several strong anchors, and re-seed from  newly found relevant papers.- Papers that use or exhibit a property: start from the defining paper or  strongest anchor, expand via similar, citers, or references, and use  read-paper to verify the property.- Superlatives and leaderboards: use general web search or scrape to find the
SKILL.md:105来自说明文档打开原文件
- When in doubt, include the relevant paper family rather than only the single  best result.- Use related-paper expansion to avoid stopping at one strong hit.- Use read-paper to verify load-bearing constraints, not to summarize every  candidate.- Drop only clearly off-topic papers.
SKILL.md:112来自说明文档打开原文件
## Parallel WorkIf appropriate, use sub-agents or equivalent parallel task runners:- Academic Papers researcher- Biomedical and Life Sciences researcher, for PubMed journal articles and  bioRxiv/medRxiv preprints on a clinical, drug, gene, disease, epidemiology,  or public-health topic- Industry Reports researcher- Technical Articles researcher- Synthesis and citation reviewer
SKILL.md:103来自说明文档打开原文件
Principles:- When in doubt, include the relevant paper family rather than only the single  best result.- Use related-paper expansion to avoid stopping at one strong hit.- Use read-paper to verify load-bearing constraints, not to summarize every  candidate.- Drop only clearly off-topic papers.

Skill 逻辑拆解

5 个说明模块

该 Skill 的主要用途是通过 Firecrawl 的托管研究接口检索、扩展、检查和阅读全文,并据此生成带来源的文献综述。

查看原文
SKILL.md:18来自说明文档打开原文件
Use this to create a sourced literature review.
SKILL.md:28来自说明文档打开原文件
Use Firecrawl Research through the CLI, MCP, or equivalent Firecrawl toolsurface as the primary path for paper discovery and verification. Fall back togeneral Firecrawl search and scrape for whitepapers, technical reports,research blogs, leaderboards, or facts outside the paper corpus.

Skill 要求提供 Firecrawl API 密钥,并允许通过 MCP、CLI 或等效工具调用服务。

查看原文
SKILL.md:10来自说明文档打开原文件
  source: https://github.com/firecrawl/firecrawl-workflowsinputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl Research, CLI, MCP, or equivalent tool requests.    required: true---

工作流会从种子论文扩展相似论文、引用和参考文献,并建议对枚举型问题采用多种查询表述和重复扩展。

查看原文
SKILL.md:47来自说明文档打开原文件
  narrow.- MCP: `firecrawl_research_related_papers(seed_ids, intent, mode?, k?)`  CLI: `firecrawl research related-papers <seedIds...> --intent <intent> [--mode <similar|citers|references>] [--k <number>]`  Expand from strong seed papers into similar work, citing papers, or  references. Use this to find the relevant paper family, not just the first  matching result.- MCP: `firecrawl_research_inspect_paper(id)`
SKILL.md:82来自说明文档打开原文件
  then expand with related papers and keep close neighbors.- Enumeration queries, such as papers that do a task or benchmark a method:  search multiple framings, expand several strong anchors, and re-seed from  newly found relevant papers.- Papers that use or exhibit a property: start from the defining paper or

最终结果要求主要论断可追溯到来源,并区分同行评审论文、博客和供应商报告。

查看原文
SKILL.md:157来自说明文档打开原文件
## Quality Bar- Every major claim should trace to a source.- Note inaccessible or failed PDFs.- Distinguish peer-reviewed work from blogs and vendor reports.
从这里开始 · 工作说明SKILL.md
firecrawl-research-papers
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。
文件与检查记录1 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明

代码和说明中提到的操作

连接外部网站
SKILL.md:8来自说明文档打开原文件
  version: "0.1.0"  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflows
SKILL.md:9来自说明文档打开原文件
  homepage: https://www.firecrawl.dev  source: https://github.com/firecrawl/firecrawl-workflowsinputs:
SKILL.md:12来自说明文档打开原文件
  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl Research, CLI, MCP, or equivalent tool requests.    required: true
读取密钥或账号配置
SKILL.md:11来自说明文档打开原文件
inputs:  - name: FIRECRAWL_API_KEY    description: Firecrawl API key for hosted Firecrawl Research, CLI, MCP, or equivalent tool requests.
读取了多少行
162
文件校验值(用于核对版本)
fa74a2d83b66bea70f38e9e25c0ae7302a59d5b8d37e03c6902866ea8af1b612