Back to skill

Security audit

Web Search by Tavily

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AIsa/Tavily web search and URL extraction wrapper that sends user-provided queries or URLs to the documented external API.

Install only if you are comfortable sending search queries and submitted URLs to AIsa's API using your AISA_API_KEY. Do not use it for confidential prompts, private documents, presigned URLs, or internal-only links unless AIsa is approved for that data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes Node scripts that require both environment-variable access (AISA_API_KEY) and outbound network access, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. This creates a governance gap: a host may grant broader capabilities than intended, making it harder to enforce least privilege or audit what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script accepts arbitrary user-supplied URLs and forwards them to a remote extraction service, enabling retrieval of content far beyond a narrow web-search function. In an agent context, this broader capability can be abused to fetch internal documentation links, pre-signed URLs, or other sensitive resources if such URLs are ever exposed to the agent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/extract.mjs (reported line 24)May include surrounding context.

js
process.exit(1);
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/extract", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/extract.mjs (reported line 24)May include surrounding context.

js
process.exit(1);
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/extract", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs arbitrary page content extraction from provided URLs, which is materially broader than the stated manifest description of AI-oriented web search. This mismatch can mislead users and downstream policy systems about the data-access scope, increasing the risk of unexpected retrieval of sensitive or proprietary page contents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This code performs an outbound HTTPS request to an external service and includes the user's query in the JSON body along with a bearer token. In an agent skill context, that creates a real data exfiltration boundary: any sensitive input supplied to the tool is transmitted to a remote operator outside the local trust boundary.

Content

Scanner excerpt · scripts/search.mjs (reported line 61)May include surrounding context.

js
body.days = days;
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/search", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This code performs an outbound HTTPS request to an external service and includes the user's query in the JSON body along with a bearer token. In an agent skill context, that creates a real data exfiltration boundary: any sensitive input supplied to the tool is transmitted to a remote operator outside the local trust boundary.

Content

Scanner excerpt · scripts/search.mjs (reported line 61)May include surrounding context.

js
body.days = days;
}

const resp = await fetch("https://api.aisa.one/apis/v1/tavily/search", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the user-provided query to an external third-party endpoint without any explicit disclosure, confirmation, or warning at runtime. This can expose sensitive prompts, internal data, or personal information if users assume the search is local or do not realize their input is being transmitted off-host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.