Back to skill

Security audit

curl-search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent curl-based web search helper, but its default search path sends queries over plaintext HTTP and its broad auto-activation/privacy scoping deserve review before installation.

Review before installing if you may search for private project names, internal URLs, credentials, incident details, or proprietary text. Prefer changing the default engine to an HTTPS endpoint and adding explicit confirmation/privacy guidance before external searches.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/search.sh:94
Finding

Search Queries Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/search.sh, lines 94–96
Vulnerability Type: Plaintext transmission of potentially sensitive search data
Risk Level: Medium

Vulnerable Code

bash
search_baidu() {
    local url="http://www.baidu.com/s?wd=${query}"
    curl -s -L "$url" -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" 2>/dev/null | \

Technical Analysis

The Baidu search function places the URL-encoded user query in an HTTP URL. Baidu is also configured as the default search engine. Consequently, invoking the skill without explicitly selecting another engine causes the initial request, including the complete query string, to be transmitted without transport encryption.

The -L option only instructs curl to follow redirects. It does not retroactively secure the initial plaintext request if Baidu redirects the client to HTTPS. An on-path attacker can therefore observe the query or alter the HTTP response before the script processes it. Because the response is transformed with sed, grep, and head and then presented as search output, attacker-injected content may also be returned to the user or consuming agent.

Attack Path

  1. A user invokes the skill without overriding its default baidu search engine.
  2. The script URL-encodes the search query and embeds it in an http://www.baidu.com/ URL.
  3. The initial request and query string cross the network without TLS protection.
  4. An on-path attacker, compromised gateway, or untrusted network operator intercepts the request.
  5. The attacker reads the search terms or modifies the plaintext response.
  6. The script processes and displays the attacker-controlled response content as search output.

Impact Assessment

Exploitation does not directly grant local operating-system privileges or execute code. Its scope is the confidentiality and integrity of searches made through the default Baidu pa ...[truncated 432 chars]

Remediation
View remediation

Remediation Suggestions

Replace the plaintext endpoint with HTTPS:

bash
local url="https://www.baidu.com/s?wd=${query}"

Restrict both initial requests and redirects to HTTPS, and make HTTP failures explicit:

bash
curl --fail-with-body --silent --show-error --location \
     --proto '=https' --proto-redir '=https' \
     "$url" \
     -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"

Do not suppress all error output with 2>/dev/null, because doing so conceals TLS, redirect, and connection failures that may be relevant to security. Apply the HTTPS-only protocol restrictions consistently to every search-engine request and add a regression test that rejects all http:// search endpoints.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script claims command-injection protection, but encode_url interpolates user-controlled input directly into a Python one-liner inside double quotes. Because shell expansion happens before Python runs, crafted input containing command substitution syntax such as $(...) can execute arbitrary shell commands when python3 -c is invoked, defeating the sanitization claim and enabling code execution in the caller's environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises shell and network-capable behavior but does not declare an explicit tool scope such as permissions or allowed-tools. That leaves the runtime with unclear execution boundaries and can permit broader-than-intended command execution or outbound requests if the hosting platform relies on manifest scoping for enforcement. The risk is increased here because the skill’s core purpose is web access via curl and shell usage, so these capabilities are not incidental.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation text uses broad phrases like 'search', 'look up', or 'query something online', which can cause the skill to trigger in many unrelated contexts. Over-broad invocation increases the chance that a shell/network-enabled skill runs unexpectedly on sensitive user input, causing unintended outbound data transmission or command execution paths. Because this skill performs web requests, accidental activation is more dangerous than for a passive, local-only skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user's query to third-party search engines over the network without any explicit disclosure, confirmation, or privacy warning. In an agent context, prompts may contain sensitive internal data, credentials, incident details, or proprietary information, so silent transmission can cause unintended data exfiltration to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The default engine is set to Baidu, and the Baidu result filtering emphasizes Chinese-language terms, which can impose a locale/language bias on users without explicit choice or explanation. This may violate the language/locale policy because the script does not clearly document that behavior as region-specific or require user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.