Back to skill

Security audit

xAI Grok Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward xAI Grok web/X search connector, but users should understand that their search queries are sent to xAI.

Install only if you are comfortable sending web/X search queries, filters, and optional media-understanding requests to xAI's API. Avoid confidential, regulated, or sensitive internal searches unless your xAI account and data-handling terms allow it, and keep the XAI_API_KEY protected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
homepage: https://github.com/yourusername/xai-grok-search
metadata:
  category: search
  api_base: https://api.x.ai/v1
  capabilities:
    - api
    - web-search

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is explicitly designed to send user-provided queries to xAI's external API, but the user-facing guidance does not clearly warn that prompts, search terms, and potentially attached media will be transmitted to a third party. This creates a real privacy and data-handling risk, especially if users assume the query stays local or do not realize X/web searches may include sensitive terms.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The URL match here corresponds to the actual outbound request path used by the web search implementation, so it is a real external transmission sink rather than a purely descriptive reference. In context, the skill is a search connector, which makes the behavior expected, but it still poses privacy risk if sensitive prompts are forwarded without clear disclosure.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
if (excluded_domains) tool.excluded_domains = excluded_domains;
  if (enable_image_understanding) tool.enable_image_understanding = true;

  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The URL match here corresponds to the actual outbound request path used by the web search implementation, so it is a real external transmission sink rather than a purely descriptive reference. In context, the skill is a search connector, which makes the behavior expected, but it still poses privacy risk if sensitive prompts are forwarded without clear disclosure.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
if (excluded_domains) tool.excluded_domains = excluded_domains;
  if (enable_image_understanding) tool.enable_image_understanding = true;

  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The URL match here is tied to the X search implementation's outbound request and therefore represents a true data egress point. Because this path can also enable media understanding, the context makes accidental disclosure more severe than a simple text-only lookup.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
if (enable_image_understanding) tool.enable_image_understanding = true;
  if (enable_video_understanding) tool.enable_video_understanding = true;

  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The URL match here is tied to the X search implementation's outbound request and therefore represents a true data egress point. Because this path can also enable media understanding, the context makes accidental disclosure more severe than a simple text-only lookup.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
if (enable_image_understanding) tool.enable_image_understanding = true;
  if (enable_video_understanding) tool.enable_video_understanding = true;

  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This code performs an outbound HTTPS request to xAI's API containing user-controlled query content and tool configuration. External transmission is inherent to the skill's purpose, but it remains security-relevant because it can exfiltrate sensitive user input, and the function returns the full raw upstream response, increasing downstream exposure of third-party data.

Content

Scanner excerpt · search.mjs (reported line 48)May include surrounding context.

js
if (enable_image_understanding) tool.enable_image_understanding = true;

  // Make API request
  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This code performs an outbound HTTPS request to xAI's API containing user-controlled query content and tool configuration. External transmission is inherent to the skill's purpose, but it remains security-relevant because it can exfiltrate sensitive user input, and the function returns the full raw upstream response, increasing downstream exposure of third-party data.

Content

Scanner excerpt · search.mjs (reported line 48)May include surrounding context.

js
if (enable_image_understanding) tool.enable_image_understanding = true;

  // Make API request
  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function sends the user-provided web search query and optional filters to xAI's external API, but the executable path provides no disclosure, consent prompt, or privacy notice before transmission. In a search skill this is expected behavior, but it is still a real privacy/security issue because users may unknowingly send sensitive prompts or internal data to a third party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This function sends X search requests to an external service over the network with user-supplied content and filters. The behavior is expected for a search integration, but it still creates a real confidentiality and data-governance risk if callers assume searches are local or if sensitive topics are submitted.

Content

Scanner excerpt · search.mjs (reported line 132)May include surrounding context.

js
if (enable_video_understanding) tool.enable_video_understanding = true;

  // Make API request
  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This function sends X search requests to an external service over the network with user-supplied content and filters. The behavior is expected for a search integration, but it still creates a real confidentiality and data-governance risk if callers assume searches are local or if sensitive topics are submitted.

Content

Scanner excerpt · search.mjs (reported line 132)May include surrounding context.

js
if (enable_video_understanding) tool.enable_video_understanding = true;

  // Make API request
  const response = await fetch('https://api.x.ai/v1/responses', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The X search path transmits the user's query and optional search constraints to xAI's external API without any warning in the executable path. Because X searches may include sensitive investigative, corporate, or personal topics, silent third-party transmission creates a meaningful confidentiality risk even if the feature is intended.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
search.mjs:24