Back to skill

Security audit

Chanai Search Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a public-web search helper, but it tells agents to fall back to shell-based curl fetching and includes off-scope search examples for password and data utilities.

Install only if you are comfortable with a search skill that may steer work toward Chinese search services and public third-party search URLs. Do not allow it to use `exec + curl` for ordinary searching, and do not use its search examples for passwords, secrets, private text transformations, or sensitive itinerary/account data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/fallbacks.md:45
Finding

Over-Privileged Shell Execution Recommended as a Network Fallback

Content
View full analysis

Vulnerability Details

File Location: references/fallbacks.md:45-50
Vulnerability Type: Command-injection risk and excessive tool privilege
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 当 `web_fetch` 被拦或返回异常
按这个顺序考虑:
1. 换一个更容易抓取的搜索页(如 DuckDuckGo HTML)
2. 改用 `site:` 查询,让结果页更干净
3. 改用 `exec` + `curl` 抓公开搜索结果页
4. 多源交叉,避免依赖单页

Equivalent exec + curl guidance also appears at lines 13 and 63.

Technical Analysis

The Skill instructs the agent to fall back from a constrained web-fetching tool to the general-purpose exec tool and curl. Shell execution provides substantially broader capabilities than necessary for public-web retrieval.

Search queries are user-controlled, and this Skill constructs URLs from those queries. The documentation does not require shell-free argument passing, destination validation, domain allowlisting, redirect restrictions, or rejection of shell metacharacters. If an agent or wrapper interpolates an attacker-controlled query or URL into a shell command, shell syntax embedded in that value could be interpreted as an additional command.

Even where command injection is avoided, unrestricted curl can reach arbitrary destinations, follow redirects, access internal services, or retrieve unexpectedly large responses unless explicit safeguards are applied. This violates least privilege because the declared functionality only requires controlled retrieval of public HTTPS search pages.

Attack Path

  1. An attacker submits a search query containing shell metacharacters or a crafted destination.
  2. The ordinary web_fetch path is blocked, times out, or otherwise fails.
  3. The agent follows references/fallbacks.md and switches to exec + curl.
  4. A vulnerable integration constructs a shell command by concatenating the query or generated URL.
  5. The shell interprets attacker-controlled syntax, potentially executing an additional local command.
  6. Alter ...[truncated 916 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the exec + curl fallback and retain a constrained web-fetching API for all network retrieval.
  2. Allow only HTTPS destinations on an explicit list of approved public search domains.
  3. Resolve and validate destination addresses before connecting; reject loopback, link-local, private, reserved, and cloud metadata addresses.
  4. Disable redirects or validate every redirect target under the same policy.
  5. If curl is operationally unavoidable, invoke it directly with a fixed argument array rather than through a shell. Never concatenate a user query into a command string.
  6. Apply strict connection and overall timeouts, response-size limits, protocol restrictions, and output-file restrictions.
  7. URL-encode user queries as data and validate the complete URL independently before retrieval.
  8. Update all equivalent recommendations at lines 13 and 63 so they cannot reintroduce the unsafe fallback.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code generally aligns with part of the description in that it generates external public-web starter URLs for Chinese and global search routes and prioritizes some human-usable destination sites for certain dynamic categories. However, the declared description overstates the workflow substantially. The script does not classify intent first, detect dynamic topics, or evaluate reliability; instead it expects route and intent as pre-supplied inputs and emits static URL templates. It also does not meaningfully implement a fallback strategy beyond including multiple search engines in a list. Additionally, although the description mentions broader workflow behavior, this code chunk is only a URL builder, and some advertised subtype handling for dynamic searches is not exposed through the command-line entry point. So the description is only partially accurate and materially broader than the code’s actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full external web search workflow operating on public web information, with search planning and routing behavior. The supplied code does none of that: it is a standalone scoring script that reads four integers from command-line arguments, sums them, assigns a reliability label, and prints JSON. While 'report reliability' is loosely related, this is only a narrow scoring helper and not the described search workflow. The code's primary purpose is materially different from the declared purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full external web search workflow with decision-making and information retrieval capabilities. The supplied code only formats command-line arguments into a structured report and Markdown summary. It does not access the web, inspect queries, classify intent, detect real-time topics, choose search providers, generate URLs, or implement fallback behavior. Reporting reliability is only superficial because the script merely prints a supplied reliability string rather than computing or evaluating it. This is a material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
- `references/international-search.md` — global-site search guidance

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill instructs the agent to invoke Python scripts and conduct external/public-web activity, but the manifest does not declare any tool scope such as permissions or allowed-tools. That creates a governance gap where network-capable behavior may be enabled without explicit least-privilege boundaries, making review, enforcement, and policy auditing harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill declares itself as the default workflow for a very broad range of external/public-web search tasks, including news, flights, prices, products, research, and other external information. Overly broad activation scope increases the chance of the skill being invoked in inappropriate contexts, which can lead to unnecessary external data exposure, overuse of network-capable tooling, and reliance on weak or irrelevant sources for sensitive queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The config includes locale-constrained search URLs such as cn.bing.com and explicitly disables English search via ensearch=0, while much of the engine list is tagged with region: "cn". This imposes a specific language/locale behavior in configuration without any indication of user opt-in or an offered alternative at the point of use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs the agent to prefer domestic/Chinese search routes by default based on content concentration, but it does not require checking or honoring the user's language, locale, or jurisdiction preferences first. This can steer users toward region-specific sources, bias results, and in some cases expose them to censored, less relevant, or compliance-sensitive content when a global or user-preferred route would be more appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file forces a specific language for instructions and reporting expectations, but it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. This creates a natural-language policy concern under the locale/language requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance explicitly expands a web-search skill into shell command execution by recommending exec + curl as a fallback. Even if intended only for public pages, introducing command execution broadens the attack surface, can enable unsafe command construction from search terms, and exceeds the least-privilege expectation for a search workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file recommends shell execution and external fetching without any warning that this involves command invocation and outbound network access. That omission can cause operators or downstream agents to treat the action as routine, reducing scrutiny around privacy, logging, and system-impact concerns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This instruction recommends using exec with curl when web_fetch is blocked, effectively bypassing the normal tool boundary and safety model. In agent contexts, such advice can lead to arbitrary command execution patterns, unsafe handling of attacker-controlled URLs or query strings, and unreviewed outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This fallback path instructs the agent to use exec and curl but does not disclose the security implications of shelling out or making direct network requests. In a search skill, this lack of warning is especially problematic because the fallback may be triggered automatically during ordinary failures.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Embedding exec + curl in a routine travel/local-info template normalizes command execution for common user requests with no strong justification. Because these workflows often involve dynamic user-supplied locations and dates, the context increases the chance that untrusted input could flow into shell commands or trigger privacy-sensitive requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The travel-related template promotes exec + curl scraping without warning about execution risk, privacy implications, or third-party access. Since travel searches can include sensitive itinerary or location information, undisclosed direct requests may expose user data and create unnecessary system/network risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill instruction set is written only in Chinese and provides no indication that the language is optional or that the skill is intended exclusively for Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This documentation expands a web-search skill into unrelated utility behaviors such as password generation, Base64 encoding/decoding, QR code generation, and UUID generation. That broadens the skill’s operational scope, can misroute user intent, and may cause users to rely on third-party search pages for sensitive or security-relevant tasks instead of purpose-built local tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide documents a parameter that disables safe search filtering without warning or justification. In a general-purpose search skill, this makes it easier for the agent to surface explicit, harmful, or otherwise unsafe content, especially if queries are user-controlled or ambiguous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples actively instruct the agent to use the search workflow for password generation, Base64 operations, color conversion, and QR code generation, which are not external-information search tasks. In practice this can cause privacy leakage of user-supplied data through query strings, create unsafe handling of secrets, and undermine least-privilege boundaries between skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is written entirely in Chinese and repeatedly prioritizes Chinese services and Chinese-language sources such as 知乎、小红书、微博、百度/必应中文. Under the policy rule for natural-language violations, this constitutes a locale/language preference that is not presented as optional or limited to a clearly documented region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill reference is written only in Chinese and does not indicate that language selection is optional or constrained to a justified region-specific use case. The policy requires flagging language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and instructions are written to require reports in Chinese, and there is no indication that users may choose another language or that the skill is limited to a Chinese-only context. This creates a natural-language policy concern because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file hard-codes Chinese-language search routes, Chinese sites, and Chinese phrasing patterns across multiple common use cases without any visible requirement to confirm the user's language, region, or consent. In a search workflow skill, this can steer user queries toward jurisdiction-specific sources and leak inferred locale/preferences, while also reducing result neutrality and potentially causing inappropriate routing for non-Chinese or privacy-sensitive requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file includes provider names and URLs such as Ctrip, Baidu, and 'Bing CN' for certain routes and subtypes, which imposes a China-specific locale/search experience by default. This is a natural-language locale policy concern because the code does not offer the user a language or regional choice, nor does it document a justified region-specific constraint in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill classifies queries using 'domestic' versus 'global' keyword hits and then preferentially returns 'domestic-first' routes and Chinese platforms such as Zhihu, Xiaohongshu, Weibo, Baidu, and Bing CN. This is a natural-language locale policy issue because the file hard-codes a regional preference and source bias without offering the user a language/locale choice or explaining that the tool is intended only for a China-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.