Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs sending a user-supplied URL to Firecrawl's external API, but it does not warn that the target URL and related request context will be disclosed to a third party. This creates a privacy and data-handling risk, especially if users provide internal, sensitive, or tokenized URLs that should not leave the local trust boundary.
