Back to skill

Security audit

Querit Search

Security checks for vulnerabilities and agentic risk

Overview

This skill provides web search and page reading, but its installer and page-fetching behavior are too broadly scoped for low-friction automatic installation.

Install only after reviewing or pinning the source, preferably from a versioned release with hashes. Avoid the one-line curl-to-bash path, do not use the content fetcher on internal or sensitive URLs, and treat search queries and fetched URLs as data shared with external services/sites.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:18
Finding

Mutable Remote Installer Is Executed Directly Through curl-to-shell

Content
View full analysis
Remediation
View remediation
querit-search-v1.0.0.tar.gz" | sha256sum -c - tar -xzf querit-search-v1.0.0.tar.gz ``` ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:7
Finding

Installer Downloads and Activates Mutable Skill Files Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
content.js:38
Finding

Unrestricted Page Fetching Exposes a Server-Side Request Forgery Primitive

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:9
Finding

Installer Omits the Lockfile and Falls Back to Mutable Dependency Resolution

Content
View full analysis
/dev/null || npm install --production --silent || error "npm install failed" ``` `package.json:7-11`: ```json "dependencies": { "@mozilla/readability": "^0.6.0", "jsdom": "^27.0.1", "turndown": "^7.2.2", "turndown-plugin-gfm": "^1.0.2" } ``` ### Technical Analysis Although the project contains a `package-lock.json` with registry URLs and integrity hashes, the installer does not include it in the downloaded file list. As a result, `npm ci` cannot use the audited lockfile and will normally fail because the lockfile is absent. The installer then silently falls back to `npm install`. The fallback resolves caret version ranges against the package registry at installation time. Consequently, users may install dependency versions different from those reviewed in this artifact. npm package lifecycle scripts may also execute unless explicitly disabled. No typosquatted or known malicious dependency was established from the reviewed files. The issue is the installation design: it discards the available reproducibility and integrity controls and expands exposure to future dependency compromise. ### Attack Path 1. The installer downloads `package.json` but not `package-lock.json`. 2. `npm ci` fails due to the missing lockfile. 3. The command falls back to `npm install`. 4. npm resolves currently available versions matching the caret ranges. 5. A compromised or malicious future dependency version can be selected. 6. The dependency's install-time code, ...[truncated 574 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (27)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Using '| bash' enables shell-command chaining from untrusted remote content, so any malicious change to install.sh is executed directly in the user's environment. In a skill ecosystem, this is especially dangerous because users may install quickly from README instructions and grant the script access to local files, tokens, and agent configuration.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

One-line installer

bash
curl -fsSL https://raw.githubusercontent.com/interskh/querit-search/main/install.sh | bash

Manual (git clone)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 60)May include surrounding context.

}

text

### Option C: .env file

Create `~/.openclaw/.env`:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a search tool returning titles, URLs, and snippets, yet it also supports --content extraction from result URLs and a separate content.js fetch path. This materially expands the trust boundary from search-query brokering to arbitrary remote content retrieval and script-to-script execution, which can expose users to unexpected data transfer and content-handling risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as a search tool returning titles, URLs, and snippets, yet it also supports --content extraction from result URLs and a separate content.js fetch path. This materially expands the trust boundary from search-query brokering to arbitrary remote content retrieval and script-to-script execution, which can expose users to unexpected data transfer and content-handling risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a search tool returning titles, URLs, and snippets, yet it also supports --content extraction from result URLs and a separate content.js fetch path. This materially expands the trust boundary from search-query brokering to arbitrary remote content retrieval and script-to-script execution, which can expose users to unexpected data transfer and content-handling risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially differs from the declared skill purpose: instead of using the Querit.ai API for search results, it performs arbitrary URL fetching and full-page extraction. In an agent environment, this expands capability from search to unrestricted remote content retrieval, which can enable SSRF-like access to internal endpoints, policy bypass, and exfiltration of sensitive page contents the manifest did not disclose.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The | bash pattern is especially risky because it removes any opportunity for inspection and causes immediate execution of whatever content is returned by the remote server. In this skill context, the same installer later performs additional remote downloads and npm installation, so a compromise at any point in the supply chain could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · install.sh (reported line 5)May include surrounding context.

sh
set -euo pipefail

# Querit Search — OpenClaw Skill Installer
# Usage: curl -fsSL https://raw.githubusercontent.com/interskh/querit-search/main/install.sh | bash

SKILL_DIR="${HOME}/.openclaw/skills/querit-search"
REPO_BASE="https://raw.githubusercontent.com/interskh/querit-search/main"

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile pins ws to 8.19.0, and the provided finding states this version is affected by a memory disclosure issue and a memory-exhaustion denial-of-service issue. Even though this skill is primarily a web search utility, jsdom brings in ws transitively; if any code path uses WebSocket functionality or parses attacker-controlled traffic through the vulnerable library, a remote attacker could trigger service instability or expose process memory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises web search and content extraction but does not clearly warn that user queries and fetched URLs are sent to external services and remote websites. This creates a privacy and data-handling risk because users or downstream agents may unknowingly exfiltrate sensitive text, targets, or browsing intent outside the local environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 62)May include surrounding context.

Option C: .env file

Create ~/.openclaw/.env:

text
QUERIT_API_KEY=your-key-here

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says OpenClaw will use the skill automatically whenever it 'needs to search the web' without defining clear boundaries or requiring explicit user confirmation. In an agent setting, this can cause overly broad automatic transmission of prompts or derived queries to an external service, increasing the chance of unintended data disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises shell, network, and environment-variable use via metadata/install steps, but it does not explicitly declare a restrictive tool scope such as permissions or allowed-tools. That makes the operational boundary unclear and can lead to broader-than-expected execution authority for a skill that handles user-supplied queries and URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation does not warn that user queries and requested URLs or extracted content are sent to an external third-party service. This is dangerous because users may unknowingly transmit sensitive prompts, internal URLs, or proprietary research targets off-platform, creating privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file header explicitly describes a content extractor, contradicting the manifest's description of a Querit.ai search skill. This discrepancy is a security-relevant transparency failure: operators and downstream agents may grant permissions or trust assumptions appropriate for search, while the code actually performs broader network retrieval and content extraction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code accepts an arbitrary URL and downloads and converts the full HTML body to markdown, which is substantially more powerful than a search-only tool. In agent deployments this can be abused to retrieve sensitive intranet/cloud-metadata pages or hidden web content and return it verbatim, making the mismatch especially dangerous because callers may trust the tool as a benign search interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer downloads multiple files from a remote GitHub repository and immediately installs Node.js dependencies, which executes code and lifecycle scripts from a package manifest the user has not reviewed. Even though this is normal installer behavior, the script provides no in-file warning about the trust implications, so users are encouraged to run untrusted remote code with little friction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package metadata and skill description claim the skill only performs web search, but the declared dependencies support HTML fetching, DOM parsing, readability extraction, and markdown conversion. That capability mismatch is security-relevant because it expands the effective trust boundary and may enable retrieval and transformation of full webpage contents beyond what users or reviewers expect.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · search.js (reported line 6)May include surrounding context.

js
// Querit Search CLI — queries the Querit.ai search API
// No external dependencies; uses Node.js built-in fetch (18+)

const API_URL = "https://api.querit.ai/v1/search";
const MAX_QUERY_LENGTH = 72;
const DEFAULT_COUNT = 5;

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description promises structured search results, but the implementation also supports fetching and extracting full page content from arbitrary result URLs via the --content flag. This expands the skill's effective data access beyond its declared purpose, increasing the chance that users or orchestrators authorize a search-only tool that can actually retrieve and expose substantially more remote content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code launches a subprocess to execute content.js for each result URL, introducing an additional capability and trust boundary not implied by the manifest's search-only scope. Even though execFile avoids shell injection, spawning a helper to fetch/process arbitrary remote pages increases attack surface and can enable unintended content access or risky downstream behavior hidden from the declared interface.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The one-line installer pipes a remote script directly into bash, which executes whatever is served at that URL at install time without prior inspection or integrity verification. If the repository, branch, hosting path, or network path is compromised, users can be exposed to immediate arbitrary code execution.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

One-line installer

bash
curl -fsSL https://raw.githubusercontent.com/interskh/querit-search/main/install.sh | bash

Manual (git clone)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The examples present English as the default language and explicitly use --lang english, while supported languages are listed later, but the documentation does not state that language choice is user-controlled or optional. This can be read as a locale preference baked into the skill behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The documented installation method uses curl to fetch a remote script from GitHub, which normalizes executing code directly from the network without prior inspection. If the repository, branch, or delivery path is compromised, users may run attacker-controlled code immediately.

Content

Scanner excerpt · install.sh (reported line 5)May include surrounding context.

sh
set -euo pipefail

# Querit Search — OpenClaw Skill Installer
# Usage: curl -fsSL https://raw.githubusercontent.com/interskh/querit-search/main/install.sh | bash

SKILL_DIR="${HOME}/.openclaw/skills/querit-search"
REPO_BASE="https://raw.githubusercontent.com/interskh/querit-search/main"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "Web search via Querit.ai API for OpenClaw",
  "license": "MIT",
  "dependencies": {
    "@mozilla/readability": "^0.6.0",
    "jsdom": "^27.0.1",
    "turndown": "^7.2.2",
    "turndown-plugin-gfm": "^1.0.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "@mozilla/readability": "^0.6.0",
    "jsdom": "^27.0.1",
    "turndown": "^7.2.2",
    "turndown-plugin-gfm": "^1.0.2"
  }

Static analysis

No suspicious patterns detected.