Back to skill

Security audit

Airweave

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it can send the Airweave API key and search queries to any base URL configured in the environment, so users should review that setup carefully.

Install only if you trust the Airweave collection and runtime environment. Verify AIRWEAVE_BASE_URL is unset or set only to a trusted HTTPS Airweave endpoint, use a least-privilege read-only key where possible, and avoid broad searches over sensitive company data unless the user explicitly wants that scope.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/search.py:71
Finding

Airweave API Credential and Sensitive Query Disclosure Through an Unrestricted Base URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a Python search script and requires environment variables containing an API key, which implies code execution, environment access, and likely outbound network access to Airweave, yet it does not declare any explicit tool scope or allowed-tools policy. This increases the risk of overbroad execution in agent runtimes, makes review and sandboxing harder, and can enable unintended data access or exfiltration if the script behavior changes or is abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed to search across connected workplace applications such as Slack, GitHub, Notion, Jira, Salesforce, and Stripe, but the description does not warn that queries may access and summarize sensitive company data. In practice, users may trigger broad retrieval without understanding the privacy implications, leading to accidental disclosure of internal documents, messages, credentials, financial records, or other sensitive business context in agent responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document labels common words like "just," "new," "current," and "now" as trigger words for high temporal bias. These terms are broad and frequently appear in ordinary queries, so using them as activation guidance without exclusions or constraints could lead to over-applying recency weighting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.