Back to skill

Security audit

Azure Bing Grounding

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Azure/Bing web-grounding helper that uses Azure credentials and sends user queries to Azure services as expected for its purpose.

Install this only if you intend to let the skill send your search queries to Azure/Bing and use your Azure project credentials. Prefer Azure CLI, managed identity, or tightly scoped short-lived credentials over storing AZURE_CLIENT_SECRET in ~/.openclaw/.env, keep that file private, and use a virtual environment with pinned dependencies where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Azure SDK Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bing_grounding.py:10
Finding

Plaintext Azure Client Secret Stored in a Shared Environment File

Content
View full analysis
str: val = os.environ.get(name) if val: return val.strip() env_path = os.path.expanduser("~/.openclaw/.env") if os.path.exists(env_path): import re with open(env_path, "r", encoding="utf-8", errors="ignore") as f: txt = f.read() m = re.search(rf"^\s*{name}\s*=\s*(.+?)\s*$", txt, re.M) if m: v = m.group(1).strip().strip('"').strip("'") if v: return v return None ``` The corresponding secret-storage guidance in `SKILL.md:24-39` includes: ```bash Add the following to your `~/.openclaw/.env` file or export them in your shell: # (Optional) Service Principal Credentials if not using DefaultAzureCredential AZURE_TENANT_ID="" AZURE_CLIENT_ID="" AZURE_CLIENT_SECRET="" ``` ### Technical Analysis The documentation recommends storing a reusable Azure service-principal secret in `~/.openclaw/.env`, and the script reads that file as ordinary plaintext. Neither the documentation nor the implementation verifies or requires restrictive ownership and file permissions. Reading the specifically named Azure configuration values is functionally related to the declared Azure Bing Grounding capability and does not, by itself, exceed the minimum privileges required when service-principal authentication is selected. The function does not enumerate unrelated files or print the loaded secret. Nevertheless, placing a long-lived credential in a shared plaintext configuration file increases its exposure to: - Other local users or processes when pe ...[truncated 1791 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bing_grounding.py (reported line 17)May include surrounding context.

python
if val:
        return val.strip()

    env_path = os.path.expanduser("~/.openclaw/.env")
    if os.path.exists(env_path):
        import re
        with open(env_path, "r", encoding="utf-8", errors="ignore") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bing_grounding.py (reported line 42)May include surrounding context.

python
if val:
        return val.strip()

    env_path = os.path.expanduser("~/.openclaw/.env")
    if os.path.exists(env_path):
        import re
        with open(env_path, "r", encoding="utf-8", errors="ignore") as f:

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/bing_grounding.py (reported line 31)May include surrounding context.

python
g="utf-8", errors="ignore") as f:
            txt = f.read()
            m = re.search(rf"^\s*{name}\s*=\s*(.+?)\s*$", txt, re.M)
            if m:
                v = m.group(1).strip().strip('"').strip("'")
                if v:
                    return v
    return None

def main():
    default_model = load_env_var("FOUNDRY_MODEL_DEPLOYMENT_NAME") or "gpt-4o"
    ap = argparse.ArgumentParser(description="Azure Bing Grounding Search Tool using Agents SDK")
    ap.add_argument("--query", required=True, help="Question or query to send to the grounded agent")
    ap.add_argument("--model", default=default_model, help="Model deployment name to use (defaults to FOUNDRY_MODEL_DEPLOYMENT_NAME or gpt-4o)")
    ap.add_argument("--format", default="raw", choices=["raw", "md"], help="Output format: raw (JSON) or md (Markdown)")
    args = ap.parse_args()

    project_endpoint = load_env_var("FOUNDRY_PROJECT_ENDPOINT")
    bing_connection_id = load_env_var("BING_PROJECT_CONNECTION_ID")

    if

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation presents the markdown output example entirely in Chinese, which implies the skill may produce or expect a specific language without offering user choice. The stated purpose of the skill is general web grounding, and the README does not document any region-specific or language-specific constraint that would justify this locale behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a local Python script and instructs users to provide Azure credentials via environment variables, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a trust boundary issue: the skill can access environment data and local files without transparent restriction metadata, making it easier for a caller or agent framework to over-grant access and accidentally expose secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends the user-supplied --query directly to Azure Agents/Bing Grounding, which forwards potentially sensitive content to an external service without any consent prompt, warning, or data-classification check. In a grounding/search skill, users may mistakenly include secrets, internal URLs, customer data, or incident details that then leave the local environment and become subject to external processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.