Back to skill

Security audit

Openclaw Multi Search Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward search-engine guide that sends user-chosen queries to listed external search providers and does not install code, persist itself, or request credentials.

Install only if you are comfortable with your search terms being sent to the selected search provider. Avoid sensitive personal, credential, medical, legal, or proprietary queries, and keep safe-search enabled when appropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- `references/international-search.md` - International search guide

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents its operational description, feature list, and usage examples entirely in Chinese, which can impose a language constraint on users without opt-in. Under the policy, forcing a specific language without offering a choice or documenting a justified regional limitation is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill routes user-provided queries directly to third-party search engines, but it does not warn users that their search terms may be transmitted to external services with different logging, tracking, and jurisdictional privacy practices. This is especially relevant because the skill emphasizes privacy engines and broad multi-engine support, which may lead users to assume privacy characteristics that do not apply uniformly across all providers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The config explicitly labels multiple engines as region "cn" and includes China-specific endpoints such as Baidu and Bing CN, but there is no natural-language indication that users can choose or opt into this locale-specific behavior. Under the policy, forcing a specific locale without user choice can be a natural-language policy concern even in config values.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides direct web_fetch examples to third-party search engines without warning that user queries will be sent to external providers, potentially logged, profiled, or associated with IP and browser metadata. In a search-integration skill, this is contextually relevant behavior, but omitting privacy disclosure can still mislead users into transmitting sensitive terms to external services unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly documents parameters for disabling safe search (kp=-1, nj=0) without any caution about exposure to adult, harmful, or workplace-inappropriate content. In an agent skill, users may copy these examples directly, increasing the chance of unsafe content retrieval or policy violations in downstream use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Natural-language content throughout the file is exclusively Chinese, and several examples prescribe specific locale settings such as hl=en, lr=lang_zh-CN, cr=countryCN, kl=cn, and language=english. For a general search guide, this can amount to a language or locale constraint without explicit user opt-in or a documented reason that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.