Back to skill

Security audit

Local Researcher

Security checks for vulnerabilities and agentic risk

Overview

The skill is a visible local-research setup guide, but its privacy claims and install instructions understate important network and code-execution risks.

Review carefully before installing. Treat the tool as network-enabled research software, not fully offline: search topics and provider API use may leave your machine. Avoid the curl-to-shell installer and unpinned clone workflow unless you independently verify the upstream source, version, and installer contents, and avoid using sensitive research topics until the privacy wording and network behavior are clear.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:18
Finding

Unverified Remote Installer Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:18-20; the same unsafe installation command is displayed by scripts/local-researcher-quickstart.py:31-34
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Complete Code Snippet (SKILL.md:18-20):

bash
# Linux
curl -fsSL https://ollama.com/install.sh | sh

Related Code Snippet (scripts/local-researcher-quickstart.py:31-34):

python
print("📥 安装指南:")
print("   macOS: brew install ollama")
print("   Linux: curl -fsSL https://ollama.com/install.sh | sh")

Technical Analysis

The installation instructions pipe data fetched from an external URL directly into a shell. The payload is not pinned to a reviewed version and is not validated using a cryptographic hash or signature before execution. Consequently, the code ultimately executed can change after this Skill has been audited.

Ollama is relevant to the Skill's declared local-LLM functionality, and the URL uses Ollama's official HTTPS domain. However, these factors do not remove the execution risk. Compromise of the distribution server, domain, release process, or applicable TLS trust chain could cause arbitrary attacker-controlled commands to be returned and immediately executed.

The Python quick-start script does not execute the installer itself; it prints the same command for the user to copy and run. Nevertheless, it promotes the same unsafe installation path.

This behavior exceeds the minimum privileges necessary to provide installation guidance. The Skill can instead direct the user to a pinned package or require separate download, verification, inspection, and execution steps.

Attack Path

  1. An attacker compromises the remote installer, its hosting infrastructure, the upstream release process, or a trusted network/certificate component.
  2. The user follows the instructions in SKILL.md or copies the command printed by the quick ...[truncated 1035 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh command from both the documentation and the quick-start output.
  2. Prefer an official package manager or a versioned, signed Ollama release.
  3. Pin the installer or package to a specific reviewed version rather than a mutable URL.
  4. Download the artifact as a separate operation and verify its publisher signature or documented SHA-256 digest before execution.
  5. Display the verification procedure and expected digest in the installation instructions.
  6. Execute installation with ordinary user privileges wherever possible, requesting narrowly scoped elevation only when required.
  7. If a script-based installer remains necessary, instruct users to download and inspect it before running it rather than piping it directly into a shell.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Mutable Upstream Repository Installed Without Version or Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39-48; equivalent commands are displayed by scripts/local-researcher-quickstart.py:57-63
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Medium

Complete Code Snippet (SKILL.md:39-48):

bash
# 克隆仓库
git clone https://github.com/langchain-ai/local-deep-researcher.git
cd local-deep-researcher

# 创建虚拟环境
python -m venv .venv
source .venv/bin/activate  # Windows: .venv\Scripts\activate

# 安装依赖
pip install -e .

Related Code Snippet (scripts/local-researcher-quickstart.py:57-63):

python
print("📥 克隆:")
print("   git clone https://github.com/langchain-ai/local-deep-researcher.git")
print("   cd local-deep-researcher")
print("   python -m venv .venv")
print("   source .venv/bin/activate")
print("   pip install -e .")

Technical Analysis

These instructions clone the mutable default branch of an external Git repository and install it in editable mode. No commit hash, signed tag, release artifact, checksum, lock file, or hash-verified dependency set is specified.

Python package installation can execute package build hooks and resolve additional dependencies. Therefore, compromise of the upstream repository or one of its dependency declarations could introduce code that executes during installation or later at runtime. A virtual environment limits package placement but is not a security sandbox: installation hooks still run with the invoking user's operating-system permissions.

The upstream project is directly related to the declared research functionality, so using it is functionally justified. The unsafe element is trusting mutable, unverified upstream content rather than a reviewed and pinned release. The quick-start script only prints these commands and does not perform the clone or installation automatically.

Attack Path

  1. An attacker compromises the upstream reposi ...[truncated 1364 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the upstream project to a specific reviewed commit or cryptographically signed release tag.
  2. Verify the signed tag, commit signature, or release artifact hash before installation.
  3. Replace the unqualified clone with explicit checkout and verification steps.
  4. Lock all transitive Python dependencies to reviewed versions and require hashes during installation.
  5. Review pyproject.toml, setup.py, build-system requirements, and dependency declarations before running pip.
  6. Prefer a non-editable installation from a verified release artifact for ordinary users.
  7. Perform installation and initial execution in an isolated, non-privileged environment without unrelated secrets.
  8. Update the quick-start script so it prints the pinned and verified procedure rather than the mutable default-branch workflow.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to be a fully local deep research assistant with specific capabilities, but the content mainly provides setup and usage guidance and does not substantiate the promised behavior. This mismatch is security-relevant because users may trust privacy, functionality, and execution boundaries that are not actually enforced or implemented.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation emphasizes local-only handling but does not adequately warn that the skill performs internet searches and sends queries to external services. This omission materially increases privacy risk because users are not given informed consent before sensitive content may be disclosed externally.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The documentation instructs users to fetch and immediately execute a remote script via curl piped to sh. This is dangerous because any compromise of the remote server, transport path, or script content results in arbitrary code execution on the user's system.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
brew install ollama

# Linux
curl -fsSL https://ollama.com/install.sh | sh

# 拉取模型
ollama pull deepseek-r1:8b

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping network content directly into a shell creates a command-execution chain with no inspection or integrity verification step. In a skill context, this is especially risky because users may follow setup instructions with elevated trust, leading to immediate compromise if the upstream content is malicious or tampered with.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
brew install ollama

# Linux
curl -fsSL https://ollama.com/install.sh | sh

# 拉取模型
ollama pull deepseek-r1:8b

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

复制环境变量模板并编辑:

bash
cp .env.example .env

编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local-researcher-quickstart.py (reported line 69)May include surrounding context.

python
复制环境变量模板并编辑:

```bash
cp .env.example .env
```

编辑 `.env` 文件:

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The privacy section states that all data stays local, directly contradicting the documented use of DuckDuckGo, Tavily, Perplexity, and other network resources. False privacy assurances are dangerous because they can induce users to expose confidential research topics, business plans, or sensitive inputs to external services.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
92% confidence
Finding

The script recommends a curl ... | sh install pattern, which executes remote content directly from the network without prior verification. If the remote server, transport, DNS, or installer script is compromised, users could run arbitrary code on their machine. In a local-research skill context, this is more dangerous because the tool is positioned as privacy/local-first, encouraging trust while directing users to execute an opaque bootstrap command.

Content

Scanner excerpt · scripts/local-researcher-quickstart.py (reported line 34)May include surrounding context.

python
print("⚠️  Ollama 未安装或未运行")
        print("📥 安装指南:")
        print("   macOS: brew install ollama")
        print("   Linux: curl -fsSL https://ollama.com/install.sh | sh")
        print("")
        print("   然后拉取模型:")
        print("   ollama pull deepseek-r1:8b")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local-researcher-quickstart.py (reported line 68)May include surrounding context.

python
# 显示使用指南
    print("📚 快速开始:\n")
    print("1. 配置环境变量:")
    print("   cp .env.example .env")
    print("   # 编辑 .env 文件")
    print("")
    print("2. 启动研究:")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents multiple shell-capable installation and execution steps but does not declare any tool scope or allowed-tools boundary. In an agent setting, missing explicit permissions increases the chance the skill is invoked with broader shell access than users expect, enabling unintended command execution during setup or use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as fully local and privacy-first, yet it explicitly performs web research and supports third-party search APIs. This can mislead users into providing sensitive topics or documents under the false assumption that no external network disclosures occur.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description is broad and lacks exclusion conditions, which can cause the skill to activate for loosely related research or document tasks. In an agent environment, overbroad triggering can unintentionally route sensitive user requests into a workflow that performs shell setup steps or external searches.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s docstrings and all user-facing messages are in Chinese, which imposes a specific language on users. Under the policy, this is a natural-language locale violation because the script does not provide opt-in, alternatives, or documentation that it is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-researcher-quickstart.py (reported line 13)May include surrounding context.

python
def check_ollama():
    """检查 Ollama 是否安装运行"""
    try:
        result = subprocess.run(
            ["ollama", "list"],
            capture_output=True,
            text=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-researcher-quickstart.py (reported line 44)May include surrounding context.

python
def check_ollama():
    """检查 Ollama 是否安装运行"""
    try:
        result = subprocess.run(
            ["ollama", "list"],
            capture_output=True,
            text=True

Static analysis

No suspicious patterns detected.