Back to skill

Security audit

AnySearch MCP

Security checks for vulnerabilities and agentic risk

Overview

The skill is a search connector, but it should be reviewed because it asks agents to create an external account with the user's email and documents unpinned proxy commands.

Install only if you are comfortable with AnySearch receiving search queries, extracted URLs, and any email you provide for account creation. Prefer anonymous or native Streamable HTTP mode, confirm before creating an account, avoid unpinned npx proxy commands where possible, and keep API keys out of shell history and logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:193
Finding

Unpinned Third-Party Proxy Packages Are Automatically Downloaded and Executed

Content
View full analysis
``` ### Technical Analysis The legacy transport configurations invoke `mcp-remote` and `supergateway` through `npx -y` without specifying exact package versions or verifying package integrity. The `-y` option suppresses the normal installation confirmation, while the absence of a version constraint allows npm to resolve and execute a package release that may differ from the one reviewed when the Skill was published. This creates a supply-chain execution boundary controlled by mutable external npm packages. If a package, package maintainer account, or package publication process is compromised, the resolved package can execute arbitrary JavaScript under the permissions of the user running the MCP client. The proxy packages are only needed for clients that do not support native Streamable HTTP. Automatically downloading mutable packages therefore exceeds the minimum privileges and trust required for clients that can connect directly. ### Attack Path 1. An attacker compromises the npm account, publication pipeline, or release artifacts of `mcp-remote` or `supergateway`. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user installs the documented legacy MCP configu ...[truncated 799 chars]
Remediation
View remediation
` or `supergateway@`. 3. Remove `-y` so installation requires explicit user approval. 4. Install dependencies separately using a lockfile and verify registry integrity hashes before execution. 5. Document the expected package publisher, version, checksum, and official source repository. 6. Run unavoidable proxy software in a restricted environment with minimal filesystem, network, and credential access. 7. Establish a dependency review and update process rather than resolving the latest package automatically at runtime. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:288
Finding

Bearer API Key May Be Exposed Through Proxy Command-Line Arguments

Content
View full analysis
``` ### Technical Analysis The proxy configurations supply the AnySearch bearer credential as a command-line argument. After placeholder or environment-variable expansion, the credential may become part of the proxy process argument vector. Depending on the operating system and client implementation, process arguments can be exposed through process-inspection interfaces, diagnostic output, application logs, shell history, crash reports, or monitoring software. This gives the credential a wider local exposure surface than a protected secret store or a proxy interface that reads credentials without placing them in process arguments. Sending the API key to `api.anysearch.com` is necessary for authenticated service use. Passing it through a third-party proxy's command line is not necessary for clients that support native Streamable HTTP and is not the minimum-risk secret-handling mechanism. ### Attack Path 1. A user configures or launches a proxy using the documented bearer-token argument. 2. The MCP client or shell expands the API-key placeholder into the command-line argument. 3. The expanded value appears in process metadata, diagnostics, logs, shell history, or a crash report. 4. A local user, monit ...[truncated 595 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The skill empowers the agent to register an external account in a single step after merely asking for an email address, without emphasizing explicit user approval for the consequential action of account creation. In an agent setting, this reduces friction for autonomous external side effects involving user identity and credentials.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Register for an API Key (Recommended)

The agent can register the user and obtain an API key in a single call — no verification code, no manual signup. Ask the user for a real email address: it becomes the account username, and a randomly generated password is emailed to it.

bash
curl -s -X POST "https://api.anysearch.com/v1/auth/email/register" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to collect a real email address and transmit it to a third-party registration endpoint, but does not require an upfront privacy notice or explicit consent explaining that personal data will be shared externally to create an account. This can lead to unauthorized disclosure of user PII and surprise account creation on an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This instruction sends a user email address to an external registration endpoint to create an account and obtain credentials. Because the flow is designed for agent-mediated transmission of personal data to a third party, it creates privacy and data-sharing risk if performed without explicit, informed consent.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

The agent can register the user and obtain an API key in a single call — no verification code, no manual signup. Ask the user for a real email address: it becomes the account username, and a randomly generated password is emailed to it.

bash
curl -s -X POST "https://api.anysearch.com/v1/auth/email/register" \
  -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This instruction sends a user email address to an external registration endpoint to create an account and obtain credentials. Because the flow is designed for agent-mediated transmission of personal data to a third party, it creates privacy and data-sharing risk if performed without explicit, informed consent.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

The agent can register the user and obtain an API key in a single call — no verification code, no manual signup. Ask the user for a real email address: it becomes the account username, and a randomly generated password is emailed to it.

bash
curl -s -X POST "https://api.anysearch.com/v1/auth/email/register" \
  -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}'

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
Error handling (always `code: -1` on error; branch on the `message` string):

| message                           | what to do                                                                                          |
| --------------------------------- | --------------------------------------------------------------------------------------------------- |
| `Invalid email address.`          | ask the user to re-enter the email                                                                  |
| `email_already_registered`        | email is taken — tell the user to sign in at `login_url`; do **not** retry                          |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The text reinforces that the agent should proceed with account-related flows using only an email address and no verification code, which lowers safeguards around external account operations. In context, this makes accidental or overly autonomous creation of third-party accounts more likely.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
| starts with `Key creation failed.` | account created but key failed — extract the email and URL from the message (`"Key creation failed. Your account <email> was created; sign in at <url>."`) and tell the user to sign in there to create a key manually |
| `Internal server error.`          | retry later or fall back to anonymous                                                               |

> The email **must be real and reachable** — the password is delivered there. There is **no verification code** in this flow; the agent only ever asks for an email.

### Get an API Key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

md
"mcp": {
    "anysearch": {
      "type": "remote",
      "url": "https://api.anysearch.com/mcp",
      "enabled": true,
      "headers": {
        "Authorization": "Bearer ${ANYSEARCH_API_KEY}",

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to execute npx -y supergateway without pinning a version, which causes retrieval and execution of the latest package from the registry at runtime. This creates a supply-chain risk: a malicious or compromised upstream release could be automatically installed and run in the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises full-page URL extraction but omits a warning that visiting user-supplied URLs sends requests to external sites and may expose request metadata or retrieve sensitive/internal content. In an agent context, this can cause unintended outbound requests, privacy leakage, or access to URLs the user did not realize would be fetched server-side.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.