Back to skill

Security audit

Tavily Search 极简版

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Tavily web search helper that sends search queries and the Tavily API key to Tavily for its intended purpose.

Install only if you are comfortable sending your search queries and selected options to Tavily and using a Tavily API key. If you use ~/.openclaw/.env, keep it limited to the needed TAVILY_API_KEY or other intended OpenClaw secrets, and review the optional README advice before changing your default OpenClaw web search behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 252)May include surrounding context.

python
)

    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            body = resp.read().decode("utf-8", errors="replace")
    except urllib.error.HTTPError as e:
        err_body = e.read().decode("utf-8", errors="replace")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 187)May include surrounding context.

python
if key:
        return key.strip()

    env_path = pathlib.Path.home() / ".openclaw" / ".env"
    if env_path.exists():
        try:
            txt = env_path.read_text(encoding="utf-8", errors="ignore")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 206)May include surrounding context.

python
if key:
        return key.strip()

    env_path = pathlib.Path.home() / ".openclaw" / ".env"
    if env_path.exists():
        try:
            txt = env_path.read_text(encoding="utf-8", errors="ignore")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README's instructional content is presented in Chinese only, with no indication that other languages are supported or that the locale restriction is intentional and justified. This can violate language/locale policy requirements because it imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill uses sensitive capabilities (environment variable access for API keys, file reads for local .env files, and outbound network access) but does not declare any explicit tool scope or permissions boundary. This weakens reviewability and least-privilege controls, making it easier for an agent runtime or user to invoke broader capabilities than expected without clear policy visibility.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
import sys
import urllib.request

TAVILY_URL = "https://api.tavily.com/search"

TAVILY_COUNTRY_CHOICES = (
    "afghanistan",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 10)May include surrounding context.

python
import sys
import urllib.request

TAVILY_URL = "https://api.tavily.com/search"

TAVILY_COUNTRY_CHOICES = (
    "afghanistan",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script transmits user queries and, when enabled, potentially large amounts of returned/raw content to a third-party search API without any runtime privacy notice or consent checkpoint. In an agent setting, users may assume local processing, so sensitive prompts, proprietary topics, or regulated data could be sent off-box unintentionally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a minimal Tavily web search skill, but this code also accesses ~/.openclaw/.env to retrieve secrets. While using an API key is expected for a search client, reading arbitrary local credential storage from the home directory is an additional local-file access capability not implied by the stated search purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language strings in comments and argparse help are written in Chinese throughout the user-facing CLI, with no option to select another language or indication that the tool is region-specific. This can violate language/locale policy when a skill imposes a language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.