Back to skill

Security audit

AIsa Search Command Center

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a normal web-research helper, but searches and submitted URLs are sent to AIsa's online API.

Install only if you are comfortable sending search terms, prompts, and target URLs to AIsa-backed online services. Use a scoped AISA_API_KEY, avoid confidential prompts or internal URLs, and use crawl/map/extract only on public or authorized sites.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires an API key and is explicitly designed to perform web-backed research, which implies network access and use of sensitive environment data, yet it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability: a host agent may permit broader execution than intended, making it easier for the skill to access env/network capabilities without clear user-visible constraints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_client.py (reported line 33)May include surrounding context.

python
class SearchClient:
    """AIsa Search API client."""

    BASE_URL = "https://api.aisa.one/apis/v1"

    def __init__(self, api_key: Optional[str] = None):
        self.api_key = api_key or os.environ.get("AISA_API_KEY")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User-supplied queries and URLs are sent to external services, but the CLI provides no clear disclosure that entered content will leave the local environment. This can cause unintentional transmission of sensitive prompts, proprietary research topics, or internal URLs to third-party providers.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description frames the tool as research/search, but the implementation also exposes broad URL extraction, crawling, and site-mapping capabilities. That scope expansion can enable collection of large amounts of third-party content or internal URLs beyond user expectations, increasing data exfiltration and misuse risk if the skill is invoked in trusted workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a research/search skill, not credential or environment access. While the API key is used to reach the external search service, reading secrets from environment variables is an additional capability that is not declared in the stated purpose and should be explicitly justified in skill metadata if relevant.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The client automatically reads AISA_API_KEY from the environment, which is a sensitive credential access pattern. Although the exception message explains the requirement when missing, the script does not clearly disclose during normal operation that it consumes a bearer token from environment state to authenticate outbound requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.