Back to skill

Security audit

MiMo 联网搜索

Security checks for vulnerabilities and agentic risk

Overview

This looks like a MiMo web-search skill, but it runs user-controlled search text through a shell command, creating a real command-injection risk.

Review before installing. Use only in a constrained environment, avoid sensitive queries, and do not expose it to untrusted user input until the shell-based curl calls are replaced with a native HTTP client or spawn/execFile argument array. Treat queries and results as data sent to Xiaomi MiMo, and avoid raw logging of secrets, personal data, or proprietary content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:68
Finding

Arbitrary Command Execution Through Shell Command Injection

Content
View full analysis

Vulnerability Details

File Location: index.js:68-75
Related Documentation Locations: SKILL.md:61-75, USAGE.md:33-47
Vulnerability Type: OS command injection through unescaped shell command construction
Risk Level: High

Vulnerable Code

javascript
// Build the curl command
const curlCommand = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
    -H "api-key: ${apiKey}" \
    -H "Content-Type: application/json" \
    -d '${JSON.stringify(requestData)}'`;

try {
  // Execute the curl command
  const { stdout, stderr } = await execPromise(curlCommand);

The same unsafe shell-command construction and execution pattern is recommended in SKILL.md:61-75 and USAGE.md:33-47.

Technical Analysis

The application constructs a single shell command containing the API key and serialized request data, then executes it with child_process.exec(). This API invokes a command shell, so shell metacharacters in interpolated values are interpreted by the shell rather than treated exclusively as data.

The user-controlled query is placed in requestData.messages[0].content before JSON.stringify(requestData) is embedded inside a shell single-quoted argument. JSON serialization only produces valid JSON; it does not perform shell escaping. In particular, a single quote in the query can terminate the shell's quoted -d argument. An attacker can then introduce shell operators, command substitutions, or additional commands.

The value of MIMO_API_KEY is also interpolated into a double-quoted shell argument. If an attacker can influence that environment variable, shell substitutions contained in it may also be evaluated.

In addition, placing the API key directly in a command-line argument can expose it to other local users or monitoring tools that are permitted to inspect process command lines.

Attack Path

  1. An attacker supplies a crafted search query to mimoWebSearch() ...[truncated 1877 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the shell-based curl invocation with Node.js fetch() or https.request(). Pass the API key through the HTTP headers object and the request body through the client API without involving a shell.
  2. If an external curl process is unavoidable, use execFile() or spawn() with an explicit argument array and shell: false. Supply the serialized body as one argument rather than concatenating it into a command string.
  3. Never interpolate user-controlled queries, environment variables, or credentials into a shell command.
  4. Update the examples in SKILL.md:61-75 and USAGE.md:33-47 so users do not copy the vulnerable pattern.
  5. Avoid exposing the API key in process arguments. A native HTTPS client is preferred because headers remain inside the process and request rather than appearing in a command line.
  6. Validate configuration fields such as model name, token limits, temperature, keyword limits, and result limits against explicit type and range constraints. Validation is defense in depth and must not replace removal of the shell.
  7. Add regression tests containing single quotes, double quotes, newlines, shell separators, and command-substitution characters. Verify that all such input is transmitted as literal request content and never interpreted by a shell.
  8. Run the skill under a least-privileged account with restricted filesystem and network access to reduce impact if another execution flaw is introduced.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README encourages use of a web search capability and shows passing arbitrary queries to an external service, but it does not warn that prompts and search terms may be transmitted off-host to a third-party API endpoint. This can lead users to submit sensitive internal data, credentials, or proprietary material under the false assumption that the operation is local or privacy-neutral.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation recommends logging search queries and results for debugging without cautioning that those logs may contain sensitive user inputs, third-party content, or confidential context sent to or returned from the external search service. If application logs are broadly accessible or retained long-term, this can create secondary data exposure even when the API call itself is expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says the skill performs online search, but it does not clearly warn that user queries are transmitted to a third-party service provider. This creates a privacy and consent issue because users may provide sensitive data assuming it remains local to the agent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are broad enough to match common conversational words like '搜索'、'查找'、'查询', which can cause the skill to activate unintentionally. In this skill, unintended activation is meaningful because it can send user-provided content to a third-party API and incur cost without clear user intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code sends conversation content to an external endpoint, which is expected for a web-search skill but still represents real data exfiltration to a third party. The risk is increased by the lack of guardrails around what may be included in the query, so sensitive prompts or user data could be transmitted unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

2. 调用联网搜索 API

bash
curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
  -H "api-key: $MIMO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code sends conversation content to an external endpoint, which is expected for a web-search skill but still represents real data exfiltration to a third party. The risk is increased by the lack of guardrails around what may be included in the query, so sensitive prompts or user data could be transmitted unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

2. 调用联网搜索 API

bash
curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
  -H "api-key: $MIMO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The JavaScript example constructs a shell command containing JSON with user-controlled query content and passes it to exec. If the query contains shell-significant characters such as quotes or command substitution syntax, this pattern can lead to command injection in addition to third-party data transmission.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

3. 在 OpenClaw 中使用

javascript
// 使用 exec 工具调用 MiMo 联网搜索
const command = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
  -H "api-key: $MIMO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '${JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs users to send search queries and conversation content to a third-party API but does not warn that prompts may contain sensitive, proprietary, or personal data. In a skill context, users may assume local tool behavior; without an explicit disclosure, this creates a real privacy and data-governance risk through unintended external transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the external API host confirms that this skill depends on a third-party network service, which creates a trust boundary and outbound data flow. In context this is not covert exfiltration, but it remains a real security concern because the documentation lacks explicit safeguards around what data may be sent and how users should assess the provider.

Content

Scanner excerpt · USAGE.md (reported line 33)May include surrounding context.

4. 在 OpenClaw 中使用

javascript
// 在 OpenClaw 会话中调用
const command = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
  -H "api-key: $MIMO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '${JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the external API host confirms that this skill depends on a third-party network service, which creates a trust boundary and outbound data flow. In context this is not covert exfiltration, but it remains a real security concern because the documentation lacks explicit safeguards around what data may be sent and how users should assess the provider.

Content

Scanner excerpt · USAGE.md (reported line 33)May include surrounding context.

4. 在 OpenClaw 中使用

javascript
// 在 OpenClaw 会话中调用
const command = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
  -H "api-key: $MIMO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '${JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The best-practice guidance recommends logging queries and results without cautioning that logs can capture sensitive prompts, returned content, or source URLs. In an agent skill, logs are often widely accessible and long-lived, so this can amplify data exposure beyond the original API transmission.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill uses child_process.exec to invoke curl for a simple HTTP API call, introducing unnecessary shell execution capability into a network-search feature. Because user-controlled query content is embedded into the JSON payload inside a single-quoted shell string, crafted input containing shell-significant characters can break quoting and lead to command injection or unintended command execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill transmits supplied query content and an API key to a third-party endpoint, which is expected for a web-search integration but still represents external data exfiltration risk if callers pass sensitive information. In this context, the danger is increased because the transmission is coupled with shell command construction, making the boundary between data handling and command execution less safe.

Content

Scanner excerpt · index.js (reported line 67)May include surrounding context.

js
}
  };

  // 构建 curl 命令
  const curlCommand = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
    -H "api-key: ${apiKey}" \
    -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code builds a curl command and executes it via child_process.exec, sending the user's query and an API key to an external service. Although comments describe the API call, there is no user-facing disclosure, confirmation prompt, or visible warning that input will be transmitted over the network through a shell command.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 68)May include surrounding context.

js
};

  // 构建 curl 命令
  const curlCommand = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \
    -H "api-key: ${apiKey}" \
    -H "Content-Type: application/json" \
    -d '${JSON.stringify(requestData)}'`;

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language descriptions and returned user-facing strings are written only in Chinese, with no indication that the user can choose another language or locale. Under the language/locale policy, forcing a specific language without opt-in can be a policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The package description is written entirely in Chinese and specifies the skill behavior in that language, with no indication that users may choose another language or locale. This can violate the language/locale policy when a skill appears to assume a fixed language without documenting opt-in or regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JavaScript test file uses Chinese-only natural-language strings in the header comment and all user-facing console output. Under the policy rule, forcing a specific language without opt-in or a documented justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.