Back to skill

Security audit

Brave Search 极简国内版

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Brave Search wrapper, but users should be deliberate about giving it a Brave API key and about any persistent tool-selection changes.

Install only if you are comfortable sending search queries to Brave Search through your configured localhost proxy and storing a Brave API key for the agent. Avoid disabling built-in web search unless you specifically want all future searches routed through this skill, and adjust the country/language defaults if CN and zh-hans are not appropriate for you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
README.md:6
Finding

Persistent Steering Toward Exclusive Use of the Skill

Content
View full analysis

Vulnerability Details

File Location: README.md:6-14
Vulnerability Type: Persistent tool-selection steering
Risk Level: Low

The documentation recommends adding a persistent instruction that directs the agent to use this Skill instead of its built-in web-search capability. It also recommends disabling the built-in web-search tool:

json
{
  "tools": {
    "web": {
      "enabled": false
    }
  }
}

Technical Analysis

These recommendations alter agent tool selection beyond an individual invocation of the Skill. If applied, the persistent agent configuration removes an independent search alternative and causes later searches to be routed preferentially through this Skill and its configured local proxy.

The behavior is classified as instruction hijacking because the documentation attempts to influence future agent decisions and suppress use of another legitimate tool. The project does not automatically modify the configuration, override safety controls, or install persistence; exploitation depends on the user manually following the documentation.

Review of scripts/brave_search.py found no credential exfiltration, shell execution, filesystem modification, obfuscated payload, remote code execution, or persistence mechanism. The script sends the documented API key to the fixed Brave Search API endpoint through a localhost proxy.

Attack Path

  1. A user installs or reviews the Skill.
  2. The user follows the README recommendation and adds the proposed tool-selection instruction to persistent agent configuration.
  3. The user disables the built-in web-search tool by setting tools.web.enabled to false.
  4. Subsequent search requests are preferentially or exclusively routed through this Skill.
  5. The agent loses the built-in search tool as an independent alternative until the configuration is reverted.

Impact Assessment

No operating-system privileges, additional credentials, co ...[truncated 442 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to disable the built-in web-search tool.
  2. Remove guidance that instructs users to add a mandatory, persistent preference for this Skill.
  3. Describe Skill selection as an optional, per-request choice.
  4. If persistent configuration is documented, clearly explain its scope, security implications, and reversal procedure.
  5. Preserve the built-in search capability as a fallback unless the user independently determines that disabling it is necessary.
  6. Replace the current guidance with neutral wording, such as: “Invoke this Skill explicitly when Brave Search through the configured localhost proxy is desired.”
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'headers' from os.environ.get (line 86, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/brave_search.py (reported line 95)May include surrounding context.

python
# 4. 发起请求
    try:
        url = "https://api.search.brave.com/res/v1/web/search"
        response = requests.get(url, params=params, headers=headers, proxies=proxies, timeout=15)
        response.raise_for_status()
        raw_data = response.json()
    except Exception as e:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

text

* 环境变量文件
```.openclaw/.env
BRAVE_SEARCH_API_KEY=your_api_key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

text

* 环境变量文件
```.openclaw/.env
BRAVE_SEARCH_API_KEY=your_api_key

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is primarily written in Chinese and includes a prescriptive instruction to add the exact Chinese phrase "搜索时请调用brave-search skill,不要用自带的web_search工具功能". This effectively imposes a specific language for invocation guidance without any user opt-in or alternative language option, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares required environment variables and explicitly performs outbound network requests, but it does not declare a corresponding tool scope such as permissions or allowed-tools. This creates a governance gap: hosts or reviewers may not have an explicit, machine-readable indication that the skill can access secrets and the network, increasing the risk of unintended data exposure or over-privileged execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description is written as a China-specific optimized tool ("针对国内代理环境做优化"), which signals a locale-specific bias without stating that this is optional. Under the policy, forcing or implicitly constraining language/locale without user choice can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The parameter table sets country default to CN and search_lang default to zh-hans, which imposes a specific locale and language by default. The file does not indicate that users are asked to opt in to these defaults or that the skill is strictly limited to a justified region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function defaults country to CN and search_lang to zh-hans, which imposes a specific locale/language behavior on users by default. The file does not indicate that this is region-specific tooling or offer an explicit opt-in before applying these locale constraints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/brave_search.py (reported line 94)May include surrounding context.

python
# 4. 发起请求
    try:
        url = "https://api.search.brave.com/res/v1/web/search"
        response = requests.get(url, params=params, headers=headers, proxies=proxies, timeout=15)
        response.raise_for_status()
        raw_data = response.json()

Static analysis

No suspicious patterns detected.