Back to skill

Security audit

universal-search

Security checks for vulnerabilities and agentic risk

Overview

This is a functional remote search skill, but it ships a reusable bearer token and can send that token and user queries to an environment-selected URL.

Review before installing. Use this only for queries you are comfortable sending to the listed third-party search endpoint, avoid secrets or private company data, and do not rely on the bundled bearer token; the publisher should remove and rotate it and constrain authorization to an approved HTTPS endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.py:14
Finding

Hard-Coded Bearer Token Exposes a Reusable API Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/search.py, line 14
Vulnerability Type: Hard-coded secret
Risk Level: High

Vulnerable Code

python
DEFAULT_SEARCH_TOKEN = "eyJhbGciOiJSUzI1NiIsImtpZCI6ImQ0MWIxZTA3LWU0NjgtNGVkNS05ZGIwLWY0NjViMGQ5MmU4ZiJ9.eyJpc3MiOiJodHRwczovL2FwaS5jb3plLmNuIiwiYXVkIjpbIk5uZUN2TGgwaGl4RHFuNlk4ZTJ2YnI2aEFZenJWd1JIIl0sImV4cCI6ODIxMDI2Njg3Njc5OSwiaWF0IjoxNzcyNjAxMTEwLCJzdWIiOiJzcGlmZmU6Ly9hcGkuY296ZS5jbi93b3JrbG9hZF9pZGVudGl0eS9pZDo3NjEzMjU3NTc2OTE4MDI0MjMzIiwic3JjIjoiaW5ib3VuZF9hdXRoX2FjY2Vzc190b2tlbl9pZDo3NjEzMjYzNzk4ODE1Njg2NzA4In0.B5SHufj3jzhI54uc3218woi1KS6606Wg6Lelj6fK11rTQK8AibKkgjitbp1guhZNE8TpPyE-nFPH9cKYHL8G94t_2V0u3TbOw6na1AgbGKEQTpyokI_7QDqwIM0o82P8VLl_cYfpHbuglhS39MTt7gw8UI2LgdAaDC8QfoZwKJZ3CQvslOrOqf2bxxSTZ7XOpizB4ShajdbbvzJywCe3EjUh6rYvJEx_i_HPBM--APB09yMUVCzQrYdo5MTrkf4ZMK-Hej3huJJXkBwX0B-symujbxJLCi5EckAoP7uQLIuna_W6JypCtb7SdofJkK3oFYgek9iYg9DlKiC1TC-BGg"

Technical Analysis

The source package embeds a bearer token as its default authentication credential. The script reads UNIVERSAL_SEARCH_TOKEN from the environment when available, but otherwise automatically uses the distributed token:

python
SEARCH_TOKEN = os.environ.get("UNIVERSAL_SEARCH_TOKEN", DEFAULT_SEARCH_TOKEN)

It subsequently places that credential into the HTTP Authorization header:

python
SEARCH_HEADERS = {
    "Authorization": f"Bearer {SEARCH_TOKEN}",
    "Content-Type": "application/json",
}

Bearer tokens grant access based solely on possession. Any person who can download, inspect, or otherwise obtain the skill package can extract the token without needing to compromise a running system. Environment-variable override support does not protect the embedded credential or prevent its reuse outside this script.

Attack Path

  1. An attacker obtains the publicly distributed skill package or its source code.
  2. The attacker opens scripts/search.py and copies DEFAULT_SEARCH_TOKEN from line 14.
  3. The a ...[truncated 1257 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed token immediately and issue a replacement, because removing it from a later version does not invalidate copies already distributed.
  2. Remove DEFAULT_SEARCH_TOKEN from the source and require UNIVERSAL_SEARCH_TOKEN to be explicitly configured.
  3. Fail securely with a clear error when the environment variable is missing, for example:
python
SEARCH_TOKEN = os.environ.get("UNIVERSAL_SEARCH_TOKEN")
if not SEARCH_TOKEN:
    raise RuntimeError("UNIVERSAL_SEARCH_TOKEN is required")
  1. Provision a separate credential for each user, deployment, or workload rather than sharing one token across all installations.
  2. Use short-lived, narrowly scoped credentials restricted to the required API, audience, and operations.
  3. Store credentials in an appropriate secret manager or protected runtime configuration rather than source control, documentation, package metadata, or default configuration.
  4. Review repository and package history for prior exposure, and rotate any related credentials that may have been derived from or distributed with this token.
  5. Enable server-side rate limiting, usage alerts, and audit logging to identify historical or future misuse.
  6. Add automated secret scanning to source-control and release pipelines to prevent credential-bearing artifacts from being published.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tainted flow: 'SEARCH_URL' from os.environ.get (line 18, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The code sends requests to a URL that can be overridden via the UNIVERSAL_SEARCH_URL environment variable, while also automatically attaching a bearer token in the Authorization header. This creates a credential exfiltration risk: anyone who can influence the environment can redirect traffic to an attacker-controlled endpoint and capture the embedded or inherited token and all user queries.

Content

Scanner excerpt · scripts/search.py (reported line 43)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            SEARCH_URL, 
            headers=SEARCH_HEADERS, 
            json=payload,

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior presents the skill as a generic high-quality search interface, but the implementation reportedly depends on a specific third-party endpoint and hardcoded bearer-token authentication that are not transparently disclosed. This mismatch is dangerous because it can hide sensitive data transmission, obscure trust boundaries, and mislead users into believing validation and confidence scoring are produced locally rather than by an external service.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
98% confidence
Finding

A long bearer/JWT-like token is hardcoded directly in the script. Hardcoded credentials are highly dangerous in distributed agent skills because anyone with code access can reuse the token, and if combined with the environment-overridable URL, the token can be silently exfiltrated to an attacker-controlled endpoint.

Content

Scanner excerpt · scripts/search.py (reported line 15)May include surrounding context.

python
#!/usr/bin/env python3
"""
全网搜索工具 - 孙永乐开发的搜索接口
支持自然语言搜索,返回结构化结果
"""

import json
import requests
import sys
import argparse
import os

# 搜索接口配置
DEFAULT_SEARCH_URL = "https://49srjp57sf.coze.site/run"
DEFAULT_SEARCH_TOKEN = "eyJhbGciOiJSUzI1NiIsImtpZCI6ImQ0MWIxZTA3LWU0NjgtNGVkNS05ZGIwLWY0NjViMGQ5MmU4ZiJ9.eyJpc3MiOiJodHRwczovL2FwaS5jb3plLmNuIiwiYXVkIjpbIk5uZUN2TGgwaGl4RHFuNlk4ZTJ2YnI2aEFZenJWd1JIIl0sImV4cCI6ODIxMDI2Njg3Njc5OSwiaWF0IjoxNzcyNjAxMTEwLCJzdWIiOiJzcGlmZmU6Ly9hcGkuY296ZS5jbi93b3JrbG9hZF9pZGVudGl0eS9pZDo3NjEzMjU3NTc2OTE4MDI0MjMzIiwic3JjIjoiaW5ib3VuZF9hdXRoX2FjY2Vzc190b2tlbl9pZDo3NjEzMjYzNzk4ODE1Njg2NzA4In0.B5SHufj3jzhI54uc3218woi1KS6606Wg6Lelj6fK11rTQK8AibKkgjitbp1guhZNE8TpPyE-nFPH9cKYHL8G94t_2V0u3TbOw6na1AgbGKEQTpyokI_7QDqwIM0o82P8VLl_cYfpHbuglhS39MTt7gw8UI2LgdAaDC8QfoZwKJZ3CQvslOrOqf2bxxSTZ7XOpizB4ShajdbbvzJywCe3EjUh6rYvJEx_i_HPBM--APB09yMUVCzQrYdo5MTrkf4ZMK-Hej3huJJXkBwX0B-symujbxJL

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares executable capabilities requiring environment variables and network access, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because users and hosting platforms cannot clearly understand or constrain what the skill may access, increasing the risk of unintended outbound requests or misuse of sensitive environment data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises a network search API and bearer-token configuration but does not warn users that their queries and possibly related context will be transmitted to an external service. This creates a privacy and data handling risk, especially if users submit sensitive prompts, internal information, or regulated data under the assumption that processing is local or trusted.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code performs external network transmission of user-supplied content to a remote service. In this skill's context, that behavior is core functionality, but it still creates privacy and data-handling risk because arbitrary user queries are sent off-box and the service response is trusted enough to display back to the user.

Content

Scanner excerpt · scripts/search.py (reported line 43)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            SEARCH_URL, 
            headers=SEARCH_HEADERS, 
            json=payload,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool transmits the user's raw search query to a third-party remote service, but the code provides no meaningful disclosure, consent flow, or warning beyond a generic 'searching' message. In an agent skill context, users may enter sensitive data assuming local processing, which can result in unintended disclosure to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The manifest description and the full markdown content are Chinese-only, with no indication that the skill supports user language preference or is intentionally limited to a specific locale or region.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings in the module docstring, CLI description, help text, and output are all Chinese-only. That forces a specific language experience without offering localization, opt-in, or an alternative language path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.