Back to skill

Security audit

Jina AI - Web Reader, Search and Deep Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Jina AI integration that sends user-provided URLs, search queries, research prompts, and a Jina API key to Jina endpoints for web reading, search, and DeepSearch.

Install only if you are comfortable sending requested URLs, search terms, research prompts, and your Jina API key to Jina AI. Avoid using it for secrets, internal-only URLs, private documents, or authenticated content unless you intend that data to leave your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/jina-reader.py (reported line 58)May include surrounding context.

python
)

    try:
        with urllib.request.urlopen(req, timeout=120) as resp:
            content = resp.read().decode("utf-8")
            print(content)
    except urllib.error.HTTPError as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code’s behavior is narrowly focused on Jina DeepSearch and is consistent with the DeepSearch portion of the description. However, the declared purpose presents the skill more broadly as covering web reading, web search, and deep research. In the supplied code chunk, only the deep research capability is implemented. Since the evaluation asks whether the declared description accurately represents what the supplied code chunk actually does, this is a description-behavior mismatch due to materially broader declared capabilities than the code demonstrates.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk is narrowly focused on one capability: searching via s.jina.ai. While that is part of the declared description, the overall declared purpose claims additional capabilities—reading webpages through r.jina.ai and performing deep multi-step research—that are absent from this code. There are no extra undeclared sensitive behaviors, and the accessed resource (s.jina.ai) is consistent with one declared function, but the description does not accurately represent this specific code chunk because it overstates the implemented functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
Or use the helper script: `scripts/jina-search.sh "<query>" [--json]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
Or use the helper script: `scripts/jina-search.sh "<query>" [--json]`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes URL fetching, web search, and deep research against Jina AI endpoints but does not warn users that supplied URLs, search queries, and potentially sensitive research prompts will be transmitted to third-party services. In a skill ecosystem, this omission can cause users or higher-level agents to unknowingly send confidential data, internal URLs, or sensitive queries off-system, creating privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares capabilities implying environment access, network access, and shell execution, but it does not define an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes autonomous invocation riskier, because the model may be able to use broader capabilities than a user expects from the manifest alone.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill sends user-provided URLs, queries, and an API key to external Jina-controlled endpoints. Although this is core to the skill's purpose and is openly disclosed, it still creates a real data-exfiltration surface if users pass sensitive URLs, authenticated targets, research prompts, or cookies via supported headers such as X-Set-Cookie.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

bash
# Site-scoped search
curl -s "https://s.jina.ai/OpenAI+GPT-5?site=reddit.com" \
  -H "Authorization: Bearer $JINA_API_KEY" \
  -H "Accept: text/plain"

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/jina-deepsearch.sh (reported line 38)May include surrounding context.

sh
# Escape the question for JSON
JSON_QUESTION=$(printf '%s' "$QUESTION" | python3 -c 'import sys,json; print(json.dumps(sys.stdin.read()))')

response=$(curl -s -w "\n%{http_code}" "https://deepsearch.jina.ai/v1/chat/completions" \
  -H "Authorization: Bearer $JINA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{

Static analysis

No suspicious patterns detected.