T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:71- Finding
Airweave API Credential and Sensitive Query Disclosure Through an Unrestricted Base URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it can send the Airweave API key and search queries to any base URL configured in the environment, so users should review that setup carefully.
Install only if you trust the Airweave collection and runtime environment. Verify AIRWEAVE_BASE_URL is unset or set only to a trusted HTTPS Airweave endpoint, use a least-privilege read-only key where possible, and avoid broad searches over sensitive company data unless the user explicitly wants that scope.
scripts/search.py:71Airweave API Credential and Sensitive Query Disclosure Through an Unrestricted Base URL
The skill invokes a Python search script and requires environment variables containing an API key, which implies code execution, environment access, and likely outbound network access to Airweave, yet it does not declare any explicit tool scope or allowed-tools policy. This increases the risk of overbroad execution in agent runtimes, makes review and sandboxing harder, and can enable unintended data access or exfiltration if the script behavior changes or is abused.
The skill is designed to search across connected workplace applications such as Slack, GitHub, Notion, Jira, Salesforce, and Stripe, but the description does not warn that queries may access and summarize sensitive company data. In practice, users may trigger broad retrieval without understanding the privacy implications, leading to accidental disclosure of internal documents, messages, credentials, financial records, or other sensitive business context in agent responses.
The document labels common words like "just," "new," "current," and "now" as trigger words for high temporal bias. These terms are broad and frequently appear in ordinary queries, so using them as activation guidance without exclusions or constraints could lead to over-applying recency weighting.
No suspicious patterns detected.