T09 · Insecure Skill Coding Practices
- Location
scripts/search_client.py:147- Finding
Undocumented Multi-Service Operations Exceed the Skill's Declared Tavily Interface
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_client.py, lines 147–257
Vulnerability Type: Undisclosed external data processing and excessive functional scope
Risk Level: MediumComplete Code Snippet
python def cmd_extract(args: argparse.Namespace) -> None: api_key = get_api_key() urls = [u.strip() for u in args.urls.split(",")] data = aisa_post(api_key, "/tavily/extract", {"urls": urls}) if "results" in data and isinstance(data["results"], list): for r in data["results"]: print(f"\n{'='*60}") print(f" URL: {r.get('url', 'Unknown')}") print(f"{'='*60}") content = r.get("raw_content", "") print(content[:3000] if content else "(no content)") else: print(json.dumps(data, indent=2)) def cmd_sonar(args: argparse.Namespace) -> None: api_key = get_api_key() endpoint_map = { "sonar": "/sonar", "sonar-pro": "/sonar-pro", "sonar-reasoning-pro": "/sonar-reasoning-pro", "sonar-deep-research": "/sonar-deep-research", } endpoint = endpoint_map.get(args.model, "/sonar") data = aisa_post(api_key, endpoint, { "model": args.model, "messages": [{"role": "user", "content": args.query}], }) print_results(data, f"Perplexity ({args.model})") def cmd_verity(args: argparse.Namespace) -> None: """Multi-source search with confidence scoring.""" api_key = get_api_key() count = args.count print(f"\nSearching across multiple sources for: \"{args.query}\"\n") # Phase 1: Parallel retrieval sources: dict[str, dict[str, Any]] = {} tasks = { "Web": ("/scholar/search/web", {"query": args.query, "max_num_results": count}), "Smart": ("/scholar/search/smart", {"query": args.query, "max_num_results": count}), "Scholar": ("/scholar/search/scholar", {"query": a ...[truncated 6067 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
web,scholar,smart,extract,sonar, andverityfrom this Tavily-specific package if they are not necessary for its declared functionality. - If these operations are intentional, document every subcommand, destination endpoint, transmitted data category, number of requests, and potential API-credit usage in
SKILL.md. - Split unrelated services into separately installable skills so users can grant only the capabilities required for a particular task.
- Require explicit user confirmation before URL extraction, multi-service searches, or resubmission of aggregated responses for synthesis.
- Validate extraction URLs and restrict allowed schemes to
https. Reject embedded credentials and consider removing sensitive query parameters before transmission. - Apply count limits consistently to every command to prevent accidental or abusive resource consumption.
- Add a dry-run or request-preview mode that displays the endpoint and payload fields without exposing the API key.
- Provide a clear privacy notice stating that queries, prompts, URLs, and aggregated results are sent to
api.aisa.one. - Consider using service-scoped API credentials if the provider supports them, preventing a Tavily-only package from accessing unrelated endpoints.
- Remove
