Back to skill

Security audit

Searxng

Security checks for vulnerabilities and agentic risk

Overview

This search skill appears purpose-built, but it deserves review because it sends user queries to a configured SearXNG server while disabling TLS certificate verification by default.

Review before installing if you may search sensitive terms or use a remote/public SearXNG instance. Prefer a localhost instance, enable certificate verification or trust a specific local CA, avoid public instances you do not control, and be aware that generic search requests may trigger this skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/searxng.py:57
Finding

TLS Certificate Verification Is Unconditionally Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/searxng.py, lines 57-62; related warning suppression at line 20
Vulnerability Type: Improper certificate validation
Risk Level: Medium

Vulnerable Code

python
# Suppress SSL warnings for local self-signed certificates
warnings.filterwarnings('ignore', message='Unverified HTTPS request')
python
# Disable SSL verification for local self-signed certs
response = httpx.get(
    f"{SEARXNG_URL}/search",
    params=params,
    timeout=30,
    verify=False  # For local self-signed certs
)

Technical Analysis

Every HTTPS request is made with verify=False, regardless of whether the configured SearXNG endpoint is local, public, or uses a publicly trusted certificate. This disables certificate-chain and hostname validation, removing HTTPS server authentication.

Although the stated purpose is compatibility with local self-signed certificates, the behavior also applies to remote instances explicitly supported by README.md. An attacker with a network position can therefore impersonate the configured SearXNG server using any certificate. Warning suppression further reduces the visibility of this insecure connection behavior.

The search query is sent as the q request parameter, and the returned JSON is trusted and rendered or emitted to downstream programs. Consequently, a successful interception can disclose searches and replace search results without detection.

Attack Path

  1. A user configures SEARXNG_URL with an HTTPS SearXNG instance, particularly a remote or public instance.
  2. The attacker obtains a network interception position, such as through a malicious Wi-Fi access point, compromised proxy, DNS manipulation, or local network compromise.
  3. The attacker presents an arbitrary TLS certificate while impersonating the configured endpoint.
  4. Because verify=False is set, the client accepts the attacker's certificate.
  5. The attacker reads the search query and returns at ...[truncated 754 chars]
Remediation
View remediation

Remediation Suggestions

  • Enable certificate verification by default:
python
response = httpx.get(
    f"{SEARXNG_URL.rstrip('/')}/search",
    params=params,
    timeout=30,
    verify=True,
)
  • If self-signed certificates must be supported, allow users to provide a specific CA certificate rather than disabling verification:
python
SEARXNG_CA_BUNDLE = os.getenv("SEARXNG_CA_BUNDLE")
verify = SEARXNG_CA_BUNDLE if SEARXNG_CA_BUNDLE else True
  • If an explicit insecure mode is retained for development, require a clearly named opt-in such as SEARXNG_INSECURE_TLS=true, display a prominent warning, and document that it must not be used with remote instances.
  • Remove the global warning filter so insecure transport is not silently hidden.
  • Prefer http://localhost only for loopback-only deployments and authenticated, certificate-validated HTTPS for remote instances.
  • Add tests confirming that invalid certificates and hostname mismatches are rejected by default.

T08 · Insecure Dependencies

Warning
Location
scripts/searxng.py:2
Finding

Runtime Dependencies Are Unpinned and Lack Integrity Constraints

Content
View full analysis

Vulnerability Details

File Location: scripts/searxng.py, lines 2-6
Vulnerability Type: Unpinned runtime dependencies and supply-chain drift
Risk Level: Medium

Vulnerable Code

python
# /// script
# requires-python = ">=3.11"
# dependencies = ["httpx", "rich"]
# ///

Technical Analysis

The PEP 723 metadata declares httpx and rich without exact versions or cryptographic hashes. The documented execution method is uv run, which may resolve and obtain dependency versions from a configured package index when the script is run.

Because no lockfile, exact version, or hash constraint is present, the reviewed source does not uniquely determine the dependency code that will execute. Future releases are accepted automatically and may introduce a compromised release, malicious transitive dependency, security regression, or incompatible behavior.

The package names are established projects, and the audited artifact contains no evidence that their current releases are malicious. The risk is nevertheless a concrete supply-chain weakness because later dependency resolution can change the effective executable code without any modification to this repository.

Attack Path

  1. A user invokes the documented uv run .../scripts/searxng.py command in an environment where the required dependencies are not already securely cached.
  2. uv resolves unconstrained versions of httpx, rich, and their transitive dependencies from the configured package index.
  3. An attacker compromises an upstream release, a transitive dependency, the selected package index, or the user's package-index configuration.
  4. The malicious or compromised package is downloaded and installed because there is no exact version or hash verification against an audited dependency set.
  5. Package installation or subsequent import executes attacker-controlled code with the privileges of the user or agent running the skill.

Impact Assessment

A compromised dependency co ...[truncated 614 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin dependencies to reviewed versions rather than unconstrained package names:
python
# /// script
# requires-python = ">=3.11,<3.13"
# dependencies = [
#   "httpx==&lt;reviewed-version&gt;",
#   "rich==&lt;reviewed-version&gt;",
# ]
# ///
  • Prefer a project-level dependency lockfile committed to the repository so direct and transitive versions are reproducible.
  • Where supported by the installation workflow, enforce package hashes using a generated requirements file with --require-hashes.
  • Ensure dependencies are obtained only from an explicitly configured trusted package index over certificate-validated HTTPS.
  • Use automated dependency monitoring, but update pins only after review and testing.
  • Generate and publish a software bill of materials for released skill versions.
  • Run dependency installation and the skill itself with least privilege and without unnecessary secrets in the environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (17)

Tainted flow: 'SEARXNG_URL' from os.getenv (line 23, credential/environment) → httpx.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request target is taken from the SEARXNG_URL environment variable and used directly for outbound network access, so whoever controls the runtime environment can redirect all queries to an arbitrary host. In this skill that risk is compounded by verify=False, which removes TLS authentication and makes silent interception or redirection of sensitive search queries easier.

Content

Scanner excerpt · scripts/searxng.py (reported line 61)May include surrounding context.

python
try:
        # Disable SSL verification for local self-signed certs
        response = httpx.get(
            f"{SEARXNG_URL}/search",
            params=params,
            timeout=30,

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · PUBLISHING_CHECKLIST.md (reported line 78)May include surrounding context.

md
1. **Review all files** - Make sure everything is polished
2. **Test one more time** - Fresh installation test
3. **Version bump if needed** - Update SKILL.md, metadata.json, CHANGELOG.md
4. **Git commit** - Clean commit message
5. **Submit to ClawdHub** - Follow ClawdHub submission process
6. **Monitor feedback** - Be ready to address issues

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that the skill is configured with verify=False by default and presents that as normal for self-signed local instances, but it does not clearly warn that this disables certificate validation. That weakens transport security and enables man-in-the-middle interception or spoofing of search traffic, especially when the configured SearXNG URL is remote or traverses untrusted networks.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The troubleshooting guidance tells users to run curl -k, which disables TLS verification and normalizes insecure connection testing. In the context of a privacy-focused search skill, encouraging -k makes unsafe transport usage more likely and can mask certificate spoofing or interception problems instead of fixing them.

Content

Scanner excerpt · README.md (reported line 138)May include surrounding context.

  1. Check your SearXNG instance is running:
    bash
    curl -k $SEARXNG_URL
    # Or: curl -k http://localhost:8080 (default)
    

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · PUBLISH.md (reported line 117)May include surrounding context.

md
If you make changes later:

1. Update version in SKILL.md and metadata.json
2. Add entry to CHANGELOG.md
3. Run: `clawdhub publish skills/searxng`

### Manage Your Skill

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly suggests using public SearXNG instances and only notes they are 'less private', but it does not clearly warn that user search queries will be transmitted to infrastructure not controlled by the user. For a search skill, this is a privacy-relevant behavior that should be disclosed more directly in the skill description.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

Using verify=False as the default is an unsafe default because it disables server certificate validation for all HTTPS requests made by the skill. In a tool that transmits user search queries, this can expose sensitive searches to interception, redirection to malicious servers, or tampering with returned content.

Content

Scanner excerpt · README.md (reported line 128)May include surrounding context.

md
## SSL/TLS Notes

The skill is configured to work with self-signed certificates (common for local SearXNG instances). If you need strict SSL verification, edit the script and change `verify=False` to `verify=True` in the httpx request.

## Troubleshooting

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill performs network access and reads configuration from environment variables, but it does not declare any explicit tool scope or permissions boundary. That can undermine user and platform expectations about what the skill is allowed to do, making accidental or unauthorized network transmission of user queries more likely.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
90% confidence
Finding

The trigger 'search for' is close to a built-in search command and can shadow or intercept expected platform behavior. This increases the chance that ordinary user requests are routed through this skill instead, causing unintended outbound queries to the configured SearXNG instance.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
90% confidence
Finding

The trigger 'search web' conflicts with a generic built-in search capability and is likely to be activated during routine use. Because the skill performs network requests, this conflict can redirect user queries to an external or misconfigured instance without clear user intent.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
88% confidence
Finding

The trigger 'find information' is highly generic and overlaps with normal assistant interactions and built-in find/search semantics. That raises the risk of accidental activation and silent transmission of user-entered content over the network.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, generic language likely to appear in normal conversation, which increases the chance of unintended invocation. Unintended activation matters here because it can cause user text to be sent over the network to the configured search instance without a clear, deliberate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as privacy-respecting but does not clearly warn that search queries are transmitted to a configured SearXNG server. If that server is remote, user prompts or sensitive search terms may leave the local environment, creating a privacy and data-handling risk through omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-entered search queries are transmitted to the configured SearXNG instance, but the CLI does not clearly warn users that their queries leave the local process and may be sent over plain HTTP or HTTPS without certificate verification. In a privacy-oriented search skill, that mismatch is especially risky because users may reasonably assume stronger confidentiality than the implementation actually provides.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Using verify=False disables TLS certificate validation, allowing man-in-the-middle attackers to intercept or modify responses from the search backend even when HTTPS is used. Because this tool handles potentially sensitive user queries and displays remote content, the unsafe default undermines both confidentiality and integrity.

Content

Scanner excerpt · scripts/searxng.py (reported line 65)May include surrounding context.

python
f"{SEARXNG_URL}/search",
            params=params,
            timeout=30,
            verify=False  # For local self-signed certs
        )
        response.raise_for_status()

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation includes an example using "--language en," which can imply an English-only default or recommended behavior without offering users a language choice. The file does not explain that language is optional or that users may select their preferred locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.