Back to skill

Security audit

Multi-source retrieval with confidence scoring - web, academic, and Tavily in one unified API

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed third-party search client that sends user queries and URLs to AIsa/Tavily APIs, with no evidence of hidden persistence or unrelated data access.

Install only if you are comfortable sending search terms, URL targets, retrieved result sets, and crawl or site-map requests to the AIsa API and its Tavily-backed endpoints. Avoid using it with secrets, confidential internal research, private URLs, localhost, internal network hosts, or access-controlled pages unless your organization has approved that data sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises network access and use of an API key via metadata (env and remote curl/Python examples), but it does not declare an explicit tool scope such as allowed tools or permissions. This can cause operators or agent frameworks to underconstrain execution, making it easier for the skill to send user queries and URLs off-platform without clear policy visibility.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example sends search queries and an authorization token to api.aisa.one, which is a clear external transmission path. In the context of an agent skill, user-provided searches may contain sensitive business, personal, or internal research data, so outbound transmission to a third party is a genuine data-exposure risk if not clearly governed.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
# Basic web search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/web?query=AI+frameworks&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Full text search (with page content)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example sends search queries and an authorization token to api.aisa.one, which is a clear external transmission path. In the context of an agent skill, user-provided searches may contain sensitive business, personal, or internal research data, so outbound transmission to a third party is a genuine data-exposure risk if not clearly governed.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
# Basic web search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/web?query=AI+frameworks&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Full text search (with page content)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The full-text search example transmits queries to an external API and explicitly requests page content, increasing the volume and sensitivity of data processed remotely. In context, this is more dangerous than ordinary search because retrieved content may include copyrighted, internal, or sensitive text that is then handled by the provider.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

Full text search (with page content)

curl -X POST "https://api.aisa.one/apis/v1/search/full?query=latest+AI+news&max_num_results=10"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The scholar search example sends research queries to an external provider with bearer-token authentication. While expected for a search skill, this is still a real confidentiality concern because academic or product research prompts can reveal strategic intent, internal projects, or proprietary interests.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

bash
# Search academic papers
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/scholar?query=transformer+models&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# With year filter

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This scholar search variant includes structured query parameters and still transmits the search terms externally. The additional filters do not reduce the core risk; the user's research interests and timing constraints may still disclose sensitive planning or analysis activity.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

With year filter

curl -X POST "https://api.aisa.one/apis/v1/scholar/search/scholar?query=LLM&max_num_results=10&as_ylo=2024&as_yhi=2025"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The smart search endpoint combines retrieval modes, which may amplify the amount of user intent and derived context sent to the provider. In an agent workflow, richer search orchestration can make the privacy impact larger because more contextualized or sensitive investigative queries are disclosed externally.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

bash
# Intelligent hybrid search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/smart?query=machine+learning+optimization&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes external search, extraction, crawl, and map operations against third-party services but does not prominently warn that user queries, supplied URLs, and potentially sensitive targets will be transmitted to external infrastructure. In an agent setting, this creates a real privacy and data-governance risk because users may assume local processing while the skill exfiltrates prompts, URLs, and retrieved content to remote APIs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The Tavily search integration sends user queries through the vendor's API stack, introducing an additional third-party data-sharing path. This is materially relevant because users may not realize their prompts are leaving the local agent environment and may also be processed by downstream integrated services.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

bash
# Tavily search
curl -X POST "https://api.aisa.one/apis/v1/tavily/search" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"query":"latest AI developments"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The extract endpoint accepts arbitrary URLs and sends them to an external service for content retrieval, which can expose internal, private, or access-controlled URLs if the skill is used carelessly. In an agent context this is more dangerous than normal web search because it can be turned into unintended third-party access, internal resource disclosure, or exfiltration of targeted page content.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
-d '{"query":"latest AI developments"}'

# Extract content from URLs
curl -X POST "https://api.aisa.one/apis/v1/tavily/extract" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"urls":["https://example.com/article"]}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The crawl endpoint instructs a third-party service to recursively fetch a target URL, which can magnify data exposure and create unintended scanning of private or sensitive sites. Because crawling follows links and increases request volume, misuse could disclose internal site structure or trigger unauthorized collection far beyond a single user-intended page.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
-d '{"urls":["https://example.com/article"]}'

# Crawl web pages
curl -X POST "https://api.aisa.one/apis/v1/tavily/crawl" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","max_depth":2}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The site-map operation can reveal the structure of a target website to an external service, which is especially sensitive if users provide internal or non-public URLs. In the skill context, this is more dangerous than ordinary search because mapping can enumerate endpoints and content organization, increasing reconnaissance risk.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
-d '{"url":"https://example.com","max_depth":2}'

# Site map
curl -X POST "https://api.aisa.one/apis/v1/tavily/map" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The explain endpoint sends a results payload to an external API for meta-analysis, which may include previously retrieved content, summaries, or citations derived from sensitive sources. This increases exposure because the skill is not only transmitting the original query but also potentially large bodies of aggregated content to a third party.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

bash
# Generate explanations with confidence scoring
curl -X POST "https://api.aisa.one/apis/v1/scholar/explain" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"results":[...],"language":"en","format":"summary"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_client.py (reported line 30)May include surrounding context.

python
class SearchClient:
    """OpenClaw Search - Web and Academic Search API Client with Confidence Scoring."""
    
    BASE_URL = "https://api.aisa.one/apis/v1"
    
    def __init__(self, api_key: Optional[str] = None):
        """Initialize the client with an API key."""

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata advertises unified search over web, academic, and Tavily, but the implementation also exposes active crawling and site-mapping endpoints. That capability expansion matters for agent security because operators may grant or invoke the skill expecting passive search only, while the skill can perform broader reconnaissance against arbitrary sites and collect more data than its description suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented example for the explain endpoint includes a fixed language parameter of "en". Because the documentation does not mention that language is configurable or selected based on user preference, it suggests an English-only default that may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.