Back to skill

Security audit

Search Agent Skill

Security checks for vulnerabilities and agentic risk

Overview

This search skill uses internet search and page fetching in a way that matches its stated purpose, with some setup and disclosure issues users should understand.

Install only if you are comfortable with a search skill sending search-related requests to external services and fetching web pages. Avoid using it for secrets, private personal information, regulated data, or sensitive business queries unless you have reviewed the provider and logging practices. Consider setting SEARCH_LANGUAGE explicitly and using a lockfile or reviewed dependency versions in controlled environments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states the skill supports various languages, but the default configuration forces SEARCH_LANGUAGE=zh-CN. This is a natural-language locale policy concern because it imposes a specific language/locale by default without clear user opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises capabilities that rely on environment-provided secrets such as SEARCH_API_KEY, but it does not declare an explicit tool scope or permissions boundary. That creates ambiguity about what runtime resources the skill may access and makes it harder to enforce least privilege or audit what sensitive capabilities are required.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'Use when' language is very broad and could cause the orchestrator to invoke this skill for many generic knowledge requests, including cases where sending the user's query to external services is unnecessary. Over-broad routing increases privacy and data exposure risk because ordinary prompts may be forwarded to search APIs or fetched websites without a sufficiently clear need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill discusses privacy and security claims but does not clearly warn users that their queries may be transmitted to third-party search APIs and arbitrary external websites for retrieval and analysis. This omission can lead to inadvertent disclosure of sensitive user data and prevents informed consent about external data sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The help output documents SEARCH_LANGUAGE with a default of zh-CN, which indicates the skill uses a specific locale by default. Under the policy, forcing a language or locale without explicit user opt-in or a clear region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration hard-codes a default locale of 'zh-CN' when SEARCH_LANGUAGE is not set. This creates a natural-language policy concern because the skill imposes a specific language by default rather than offering a user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 80)May include surrounding context.

js
// In production, this would integrate with actual search APIs
  
  const searchEndpoints = {
    general: 'https://api.search.com/general',
    news: 'https://api.search.com/news',
    academic: 'https://api.scholar.com/search',
    code: 'https://api.github.com/search',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 81)May include surrounding context.

js
// In production, this would integrate with actual search APIs
  
  const searchEndpoints = {
    general: 'https://api.search.com/general',
    news: 'https://api.search.com/news',
    academic: 'https://api.scholar.com/search',
    code: 'https://api.github.com/search',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 84)May include surrounding context.

js
// In production, this would integrate with actual search APIs
  
  const searchEndpoints = {
    general: 'https://api.search.com/general',
    news: 'https://api.search.com/news',
    academic: 'https://api.scholar.com/search',
    code: 'https://api.github.com/search',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 82)May include surrounding context.

js
const searchEndpoints = {
    general: 'https://api.search.com/general',
    news: 'https://api.search.com/news',
    academic: 'https://api.scholar.com/search',
    code: 'https://api.github.com/search',
    images: 'https://api.search.com/images'
  };

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 83)May include surrounding context.

js
general: 'https://api.search.com/general',
    news: 'https://api.search.com/news',
    academic: 'https://api.scholar.com/search',
    code: 'https://api.github.com/search',
    images: 'https://api.search.com/images'
  };

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description says the skill is an "AI-powered search agent" that performs web searches and summarization, but it does not define specific trigger phrases, scope boundaries, or exclusion conditions, which could lead to overly broad invocation for many generic research or search-related requests.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
82% confidence
Finding

Using a caret range for a runtime dependency allows future installs to resolve to newer minor or patch releases that have not been tested or reviewed with this skill. In a search agent that fetches and processes remote content, a compromised or vulnerable dependency could affect request handling, SSRF controls, or data processing in production.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
},
  "homepage": "https://github.com/clawhub/search-agent#readme",
  "dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0-rc.12"
  },
  "devDependencies": {

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest uses an unpinned axios version despite known advisories affecting some axios releases, so the actual installed dependency may be vulnerable and cannot be verified from this file. This matters more in a search agent because it makes outbound web requests and may process attacker-controlled URLs, redirects, and proxy settings, increasing the relevance of SSRF and request-manipulation issues.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 48)May include surrounding context.

json
"cheerio": "^1.0.0-rc.12"
  },
  "devDependencies": {
    "eslint": "^8.55.0",
    "jest": "^29.7.0",
    "prettier": "^3.1.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 49)May include surrounding context.

json
},
  "devDependencies": {
    "eslint": "^8.55.0",
    "jest": "^29.7.0",
    "prettier": "^3.1.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 50)May include surrounding context.

json
"devDependencies": {
    "eslint": "^8.55.0",
    "jest": "^29.7.0",
    "prettier": "^3.1.0"
  },
  "engines": {
    "node": ">=16.0.0"

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:14