firecrawl / firecrawl/firecrawl-workflows

Address security risks flagged in risk assessment sweep

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
161
Forks
36
Avg merge
6h 53m
Merged PRs (30d)
1

Description

## Security Risk Assessments need to be addressed

A security risk assessment sweep across the Firecrawl skills/workflows surfaced several flagged items that we need to triage and remediate. Transcribed from the assessment dashboard below (Gen / Socket / Snyk scanners).

### Highest priority
- **`firecrawl-website-design-clone`** — **High Risk (Gen)**
- **`firecrawl-demo-walkthrough`** — **High Risk (Snyk)**

### Full results

| Skill / Workflow | Gen | Socket | Snyk |
| --- | --- | --- | --- |
| firecrawl-company-directories | Safe | 0 alerts | Med Risk |
| firecrawl-competitive-intel | Safe | 0 alerts | Med Risk |
| firecrawl-dashboard-reporting | Safe | 0 alerts | Low Risk |
| firecrawl-deep-research | Safe | 0 alerts | Med Risk |
| firecrawl-demo-walkthrough | Safe | 0 alerts | **High Risk** |
| firecrawl-knowledge-base | Safe | 0 alerts | Med Risk |
| firecrawl-knowledge-ingest | Safe | 0 alerts | Med Risk |
| firecrawl-lead-gen | Safe | 0 alerts | Med Risk |
| firecrawl-lead-research | Safe | 0 alerts | Med Risk |
| firecrawl-market-research | Safe | 0 alerts | Med Risk |
| firecrawl-qa | Safe | 0 alerts | Med Risk |
| firecrawl-research-papers | Safe | 0 alerts | Med Risk |
| firecrawl-seo-audit | Safe | 0 alerts | Med Risk |
| firecrawl-shop | Safe | 0 alerts | Med Risk |
| firecrawl-website-design-clone | **High Risk** | 0 alerts | Med Risk |
| firecrawl-workflows | Safe | 0 alerts | Med Risk |

Details: https://skills.sh/firecrawl/firecrawl-workflows

### Asks
- [ ] Triage the two **High Risk** items first (`website-design-clone`, `demo-walkthrough`)
- [ ] Review the widespread **Med Risk (Snyk)** findings — likely a shared dependency; bumping it may clear most rows at once
- [ ] Document remediation / accepted-risk decisions per skill

_Source: Security Risk Assessments dashboard screenshot (2026-06-24)._

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the skills.sh assessment details for firecrawl-website-design-clone and firecrawl-demo-walkthrough, then compare the widespread Snyk medium-risk findings for a shared dependency. Done means the two high-risk items are triaged and remediated, shared findings are reviewed, and remediation or accepted-risk decisions are documented for each skill.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.