Back to skill

Security audit

Grokified web research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed web-research helper that sends user questions to Grokified for live search and citations.

Install only if you are comfortable sending research questions and your Grokified API key to Grokified. Do not use it with secrets, personal data, private source code, confidential documents, or internal-only business information, and verify important cited facts from the original sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell execution via bash {baseDir}/scripts/research.sh, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a capability/transparency gap: the runtime may permit shell use without clear least-privilege declaration, making review and policy enforcement harder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill sends user-supplied questions to api.grokified.com and enables server-side web search, which is an external data transmission boundary. Even though the documentation warns not to include secrets or private code, users may still provide sensitive content, causing unintentional disclosure to a third party.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
# Grokified web research

Asks a Grok model a question through the Grokified API (`https://api.grokified.com/v1`, OpenAI-compatible) with the built-in `web_search` tool turned on. The model searches and reads pages itself on the server, then answers with inline links and a list of sources.

## When to use

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## Before the first run

1. Check that `GROKIFIED_API_KEY` is set in the environment. If it is not, tell the user to create a key at https://grokified.com/login and export it. Never ask the user to paste the key into the chat, and never print it.
2. Tell the user, once per session, that the question is sent to `api.grokified.com`. Do not put secrets, personal data or private code in the question.

## Run it

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
# Optional: GROKIFIED_MODEL (default grok-4.7).
set -euo pipefail

BASE_URL="https://api.grokified.com/v1"
MODEL="${GROKIFIED_MODEL:-grok-4.7}"

die() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/research.sh (reported line 9)May include surrounding context.

sh
# Optional: GROKIFIED_MODEL (default grok-4.7).
set -euo pipefail

BASE_URL="https://api.grokified.com/v1"
MODEL="${GROKIFIED_MODEL:-grok-4.7}"

die() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The script sends user-supplied questions, optional domain filters, and the API bearer token to an external third-party service. This is a real data-exposure boundary: if the skill is used with sensitive prompts or in a trusted automation context, confidential data may be transmitted off-host to Grokified and further expanded through live web search.

Content

Scanner excerpt · scripts/research.sh (reported line 54)May include surrounding context.

sh
then {type: "web_search", filters: {allowed_domains: $d}}
                else {type: "web_search"} end ]
     }' --args "$@" |
    curl -sS --max-time 240 -o "$resp_file" -w '%{http_code}' \
      -X POST "$BASE_URL/responses" \
      --config <(printf 'header = "Authorization: Bearer %s"\n' "$GROKIFIED_API_KEY") \
      -H "Content-Type: application/json" \

Static analysis

No suspicious patterns detected.