Back to skill

Security audit

Web Search Tavily

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AIsa/Tavily web search and URL extraction wrapper that sends requested queries or URLs to AIsa using an API key.

Install only if you intend to use AIsa/Tavily and are comfortable sending search queries, requested URLs, and the AISA_API_KEY bearer token to api.aisa.one. Do not use the extract command on private, internal, or secret-bearing URLs unless that disclosure is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes Node scripts that require environment access and outbound network access, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. This creates a least-privilege and transparency gap: a host may grant broader capabilities than users expect, increasing the risk of secret exposure or unintended external requests if the scripts are modified or abused.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts arbitrary CLI-supplied URLs and forwards them to an external extraction API without meaningful restriction. In the context of a skill presented as web search, this expands capability into arbitrary remote content retrieval, which can be abused to pull sensitive intranet, tokenized, or private-resource URLs if an agent passes them through.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/extract.mjs (reported line 24)May include surrounding context.

js
process.exit(1);
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/extract", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/extract.mjs (reported line 24)May include surrounding context.

js
process.exit(1);
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/extract", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.mjs (reported line 61)May include surrounding context.

js
process.exit(1);
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/extract", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script implements arbitrary URL content extraction via Tavily's extract endpoint, while the skill metadata describes AI-optimized web search. This mismatch is security-relevant because users or downstream agents may authorize a search tool but actually grant a content-fetching/exfiltration capability that can retrieve and transmit full page contents from attacker-chosen URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User-supplied URLs are transmitted to a third-party API endpoint, which may disclose sensitive query parameters, private document locations, or internal resource identifiers. There is no user-facing warning, consent flow, or minimization of transmitted data, so agents may unknowingly leak targets to the external provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.mjs (reported line 61)May include surrounding context.

js
body.days = days;
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/search", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes an AI-optimized web search skill, but does not mention accessing local process environment data. Although the API key is used to authenticate the expected outbound search request, reading environment variables is still a distinct local-capability dependency not stated in the skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the user-provided query and request parameters to a third-party API via an HTTP POST request. Although the script name suggests search functionality, the file itself provides no user-facing notice beyond usage text that the query will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.