other
- Location
src/clawhub-api.js:74- Finding
Undisclosed Disclosure of Search Queries to a Third-Party Mirror
- Content
View full analysis
axios.get(mirrorUrl, { params }), { maxRetries: 3, retryDelay: 1000, retryMultiplier: 2, retryableStatusCodes: [429, 500, 502, 503, 504] }); ``` The documentation identifies `https://clawhub.ai` as the homepage, and the corresponding source adapter describes itself as the official ClawHub source. However, skill searches made through that adapter are always sent to `https://skills.volces.com/api/v1/search`. The transmitted `q` parameter contains the translated search query. This may include user interests, project names, internal technologies, or other sensitive contextual information. Because default searches query all registered sources, disclosure occurs without the user explicitly selecting or consenting to this mirror. ### Technical Analysis This is a transparency and data-boundary issue rather than arbitrary code execution. The third-party endpoint is hardcoded, is not identified in `SKILL.md`, and cannot be disabled through the documented CLI options. HTTPS protects the query in transit, but the operator of `skills.volces.com` can still receive and retain the query, source IP address, request time, and ordinary HTTP metadata. The implementation does not communicate a retention policy or obtain explicit consent. ### Attack Path 1. A user runs a normal search or recommendation command containing confidential terms. 2. `SearchEngine.search()` dispatches the query through `SourceManager.searchAll()`. 3. The source labeled `clawhub` invokes `ClawHubAPI.searchSkills ...[truncated 582 chars]- Remediation
View remediation
