Back to skill

Security audit

Research Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Tavily-powered research and report generator, with cautions around third-party query sharing and user-chosen output files.

Install only if you are comfortable sending research topics to Tavily. Do not include secrets, private customer data, or confidential strategy in queries, and use simple report filenames in a safe working directory because --output can replace an existing writable file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/research.mjs:43
Finding

Unrestricted File Overwrite Through the Output Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares that it requires environment variables and performs network-backed research, but it does not explicitly constrain or disclose tool scope via permissions or allowed-tools metadata. This creates ambiguity about what runtime capabilities the skill is expected to use, which can lead to overbroad execution in hosting environments and weaken reviewability of external data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description highlights research features but does not warn that user-supplied topics will be sent to an external service via Tavily web/API requests. Users may provide sensitive internal project names, customer data, or strategic questions under the assumption analysis is local, causing unintended third-party disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded use of the Tavily external endpoint means this skill inherently depends on a remote service and sends request metadata plus search content off-host. In the context of a research tool this is expected behavior, but it is still security-relevant because users may assume local processing and accidentally disclose sensitive information to a third party.

Content

Scanner excerpt · scripts/research.mjs (reported line 75)May include surrounding context.

js
console.log('🔍 Searching...');
    
    const resp = await fetch('https://api.tavily.com/search', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded use of the Tavily external endpoint means this skill inherently depends on a remote service and sends request metadata plus search content off-host. In the context of a research tool this is expected behavior, but it is still security-relevant because users may assume local processing and accidentally disclose sensitive information to a third party.

Content

Scanner excerpt · scripts/research.mjs (reported line 75)May include surrounding context.

js
console.log('🔍 Searching...');
    
    const resp = await fetch('https://api.tavily.com/search', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes user-facing descriptions and CLI help/output in Chinese, which effectively imposes a specific language on users. The file does not present an option to select another language or document that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.