Back to skill

Security audit

Literature Search Workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a plausible literature-search workflow, but it embeds a Tavily API key and under-discloses important runtime behavior.

Review this before installing. It is not clearly malicious, but the bundled hard-coded Tavily credential should be removed and rotated, external query disclosure should be added, triggers should be narrowed, and the documentation should be aligned with the actual single-provider implementation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/literature_search.py:15
Finding

Hard-Coded Tavily API Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/literature_search.py:15
Vulnerability Type: Hard-coded API secret
Risk Level: High

Vulnerable Code:

python
TAVILY_API_KEY = os.getenv('TAVILY_API_KEY', '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')

Technical Analysis

The script embeds a usable-looking Tavily API credential as the default value passed to os.getenv. If TAVILY_API_KEY is not configured in the runtime environment, the application automatically authenticates with the credential stored in source code.

Secrets embedded in a distributed skill package cannot be kept confidential. Anyone who can download the package, inspect source-control history, access a build artifact, or read an installed copy can recover the credential without executing the script. Environment-variable support does not mitigate this exposure because the hard-coded fallback remains present.

The credential is subsequently placed in a bearer authorization header and sent to Tavily by tavily_search:

python
headers = {"Authorization": f"Bearer {TAVILY_API_KEY}"}

Attack Path

  1. An attacker obtains the published skill package or an installed copy.
  2. The attacker opens scripts/literature_search.py and reads line 15.
  3. The attacker extracts the embedded Tavily bearer credential.
  4. The attacker sends requests directly to the Tavily API using that credential.
  5. Requests are attributed to the credential owner until the key is revoked, rotated, disabled, or exhausted.

Impact Assessment

Exploitation does not grant local operating-system privileges or code execution on a victim host. It grants unauthorized use of the Tavily API within the permissions assigned to the exposed key.

Potential effects include unauthorized searches, consumption of API quota, possible billing exposure, service disruption through quota exhaustion, and reduced accountability because attacker requests may appear to o ...[truncated 156 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed Tavily credential immediately; deleting it from the current source file does not invalidate copies already distributed.

  2. Remove the hard-coded fallback and require explicit secret provisioning:

    python
    TAVILY_API_KEY = os.getenv("TAVILY_API_KEY")
    if not TAVILY_API_KEY:
        raise RuntimeError("TAVILY_API_KEY is required")
    
  3. Store the replacement credential in an approved secret manager or protected runtime environment variable, never in source code, documentation, package metadata, examples, or committed configuration files.

  4. Review repository history, release archives, build logs, and published artifacts for additional copies. Rewrite history where appropriate, while treating rotation as the primary containment measure.

  5. Review Tavily usage and billing records for anomalous activity associated with the exposed key.

  6. Apply provider-side restrictions and least-privilege controls where supported, including conservative quotas, spending alerts, expiration, and scoped access.

  7. Add automated secret scanning to pre-commit and CI/CD workflows to prevent future credential publication.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tainted flow: 'headers' from os.getenv (line 22, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/literature_search.py (reported line 29)May include surrounding context.

python
"include_answer": True,
        "max_results": max_results
    }
    response = requests.post(url, json=data, headers=headers, timeout=30)
    return response.json()

def analyze_query(query):

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior overstates the implemented capabilities and omits operationally relevant actions such as direct network access and file writes. This mismatch is dangerous because reviewers and users may trust the skill to use only declared academic integrations, while the actual implementation could perform broader actions without clear oversight or consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permissions while the documented workflow implies network access, file output, and use of external services. Missing permission boundaries can cause the runtime to grant broader capabilities than reviewers expect, increasing the risk of unintended outbound requests, local file writes, or secret exposure through environment-backed API usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The overview and most operational guidance are written in Chinese, which effectively forces a specific language for users reading the skill documentation. The policy allows locale constraints only when users are given a choice or the constraint is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger keywords are very broad and include generic phrases such as '论文搜索', 'search literature', and 'find papers', which can match many ordinary research-related requests outside the intended workflow scope. This increases the chance of unintended automatic activation, causing the agent to invoke this skill when a narrower or safer tool selection process would be more appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and presents the workflow behavior as standardized in that language, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when the skill implicitly enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes relatively broad phrases such as 'search literature', 'find papers', and general Chinese equivalents that could match ordinary user requests and invoke the workflow unintentionally. Because this skill chains multiple external search and fetch capabilities, accidental activation can lead to unnecessary external queries, data exposure in outbound requests, and execution of a more powerful workflow than the user intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

User-facing strings, report headings, and workflow messages are consistently hardcoded in Chinese, and the script does not provide any language or locale selection. This can violate language/locale policy when users are not given an opt-in or alternative output language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow sends raw user queries to a third-party search API without any consent gate, warning, or sensitivity filtering. In a literature-search context, queries may contain unpublished research topics, patient terms, internal project names, or other confidential information that would be disclosed externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/literature_search.py (reported line 21)May include surrounding context.

python
def tavily_search(query, max_results=10):
    """Tavily 搜索"""
    url = "https://api.tavily.com/search"
    headers = {"Authorization": f"Bearer {TAVILY_API_KEY}"}
    data = {
        "query": query,

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The function transmits user-supplied query content to an external web service. In this skill's context, literature queries can contain sensitive academic, medical, or organizational information, so outbound transmission to a third party creates a real confidentiality risk if users are not clearly informed.

Content

Scanner excerpt · scripts/literature_search.py (reported line 29)May include surrounding context.

python
"include_answer": True,
        "max_results": max_results
    }
    response = requests.post(url, json=data, headers=headers, timeout=30)
    return response.json()

def analyze_query(query):

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a complete literature-search workflow integrating tavily-search, pubmed-database, bgpt-paper-search, openalex-database, and literature acquisition. In the actual workflow, only Tavily is called; PubMed/BGPT and full-text acquisition are mentioned only in comments and never executed, so the implemented behavior falls materially short of the claimed workflow scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest focuses on literature search and acquisition workflow, but this script persists results as a local markdown file. Local file output is not necessarily implied by the description and is an extra behavior beyond the stated search process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script saves search results to a local markdown file, which affects user data and the local filesystem. While it announces the saved filename afterward, there is no advance warning in comments, docstrings, or a user-facing notice that running the workflow will create a file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.