Back to skill

Security audit

openclaw-china-search-tips

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its advertised purpose (China-friendly search with multiple backends) but contains several mismatches and sloppy/odd code (undeclared env vars, an unexpected search endpoint, and a logic bug that can treat empty results as success).

Things to check before installing/use: - Do not export sensitive global credentials until you confirm the endpoints. The skill asks you to set VOLC_SEARCH_API_KEY / TAVILY_API_KEY / SEARCHAPI_API_KEY, but the registry metadata does not declare them — that discrepancy is sloppy and could cause surprise. - Inspect and verify the endpoints in the bundled code. The volcengine handler posts to https://open.feedcoopapi.com/search_api/web_search which is not an obvious volcengine domain; confirm this host is legitimate before sending an API key. - Be aware of a functional bug: try_volcengine returns an empty list on some successful HTTP responses, and the main search() treats any non-None return value (including empty list) as success. This may cause the skill to report success but return no results. - If you plan to use the multi-search fallback, review or install the multi_search_engine package separately and inspect its behavior. - Prefer creating dedicated, least-privileged API keys (not reuse highly privileged tokens) and test the skill in a sandbox environment first. If unsure, ask the publisher to update the registry metadata to declare required env vars and to explain the volcengine endpoint.

Static analysis

No suspicious patterns detected.