Back to skill

Security audit

Intelligent search for agents. Multi-source retrieval with confidence scoring - web, academic, and Tavily in one unified API

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent search helper, but using it sends queries, URLs, and result data to external AIsa/Tavily-backed services.

Install only if you are comfortable using an external search provider with your AISA_API_KEY. Do not submit secrets, proprietary project terms, internal URLs, authenticated pages, or private documents to the search, extract, crawl, map, or explain operations unless your organization approves that external processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and demonstrates network access and use of an API key via environment variables, but it does not declare explicit tool scope such as allowed tools or permissions. This weakens policy enforcement and user awareness because an agent may invoke networked behavior and access secrets without a clearly bounded permission model in the skill manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation repeatedly shows sending user queries, URLs, and potentially page content to a third-party API, including crawl and extract operations, but it provides no explicit privacy or data-sharing warning. In an agent setting, users may unknowingly disclose sensitive prompts, internal URLs, or proprietary content to the external provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The referenced external domain indicates reliance on a third-party network service for handling search requests. While normal for this skill's purpose, it creates an external data-transfer boundary that should be explicitly disclosed and constrained because queries and authentication headers leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
# Basic web search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/web?query=AI+frameworks&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Full text search (with page content)

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The referenced external domain indicates reliance on a third-party network service for handling search requests. While normal for this skill's purpose, it creates an external data-transfer boundary that should be explicitly disclosed and constrained because queries and authentication headers leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
# Basic web search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/web?query=AI+frameworks&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Full text search (with page content)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The full-text search example may send not only a query but also request page content from an external service, increasing the volume and sensitivity of transmitted data. This raises privacy and confidentiality concerns if users search for or retrieve internal, regulated, or otherwise sensitive material.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

Full text search (with page content)

curl -X POST "https://api.aisa.one/apis/v1/search/full?query=latest+AI+news&max_num_results=10"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The academic search request transmits user queries to an external provider with bearer-token authentication. This is consistent with the skill's design, but it remains a true exposure point because sensitive research topics or internal project terms may be disclosed to a third party without explicit warning.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

bash
# Search academic papers
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/scholar?query=transformer+models&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

# With year filter

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The year-filtered scholar search similarly sends user-entered content to an external API, with only minor differences in parameters. The main risk is data disclosure to a third party rather than direct exploitation, especially in enterprise or research environments where query terms may be sensitive.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

With year filter

curl -X POST "https://api.aisa.one/apis/v1/scholar/search/scholar?query=LLM&max_num_results=10&as_ylo=2024&as_yhi=2025"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The smart-search endpoint combines sources and sends the user's query to an external service for broader retrieval. Because the skill emphasizes aggregation and reasoning across systems, the context increases the likelihood of wider data sharing and provider-side processing beyond what a user may expect.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

bash
# Intelligent hybrid search
curl -X POST "https://api.aisa.one/apis/v1/scholar/search/smart?query=machine+learning+optimization&max_num_results=10" \
  -H "Authorization: Bearer $AISA_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The Tavily search example posts a JSON query body to an external API, which clearly transmits user input off-platform. This is expected behavior for search, but without privacy disclosures users may unknowingly send confidential prompts, and the integration expands the set of external processors involved.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

bash
# Tavily search
curl -X POST "https://api.aisa.one/apis/v1/tavily/search" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"query":"latest AI developments"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The extract-content example sends arbitrary URLs to an external service, which can cause third-party fetching and processing of linked resources. In an agent context this is more dangerous than plain search because users may supply internal, pre-authenticated, or sensitive URLs, potentially exposing private locations, documents, or metadata to an outside provider.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
-d '{"query":"latest AI developments"}'

# Extract content from URLs
curl -X POST "https://api.aisa.one/apis/v1/tavily/extract" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"urls":["https://example.com/article"]}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The crawl example instructs an external service to recursively fetch a target URL, amplifying the privacy and security risk beyond a single request. If pointed at internal sites, staging systems, or sensitive web apps, it could disclose site structure and contents to a third party and create unintended scanning behavior.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
-d '{"urls":["https://example.com/article"]}'

# Crawl web pages
curl -X POST "https://api.aisa.one/apis/v1/tavily/crawl" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","max_depth":2}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The site-map operation sends a target URL to an external provider to enumerate site structure, which can reveal sensitive information about a website's organization if misused. In agent workflows, this can expose internal endpoints, unpublished sections, or reconnaissance data to a third party without adequate disclosure.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
-d '{"url":"https://example.com","max_depth":2}'

# Site map
curl -X POST "https://api.aisa.one/apis/v1/tavily/map" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The explain endpoint transmits a results payload for external meta-analysis, which may contain snippets, citations, or content aggregated from prior searches. This extends data exposure beyond the original query because intermediate results are also sent to a third party, yet the documentation does not explain the privacy implications.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

bash
# Generate explanations with confidence scoring
curl -X POST "https://api.aisa.one/apis/v1/scholar/explain" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"results":[...],"language":"en","format":"summary"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_client.py (reported line 30)May include surrounding context.

python
class SearchClient:
    """OpenClaw Search - Web and Academic Search API Client with Confidence Scoring."""
    
    BASE_URL = "https://api.aisa.one/apis/v1"
    
    def __init__(self, api_key: Optional[str] = None):
        """Initialize the client with an API key."""

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description frames the skill as an intelligent multi-source retrieval/search API. In addition to search and extraction, the code implements tavily_crawl and tavily_map, which expand the capability from retrieval into active crawling and sitemap discovery across sites; those are broader behaviors than the stated search-focused scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example for the explain endpoint includes a JSON body with "language":"en", which presents English as the fixed output language. Because the documentation does not indicate that language is configurable or user-selectable, this can be read as forcing a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.