Back to skill

Security audit

Google Web Search

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Google search skill, but it can expose the user's Google API key in error output.

Review this before installing if you care about protecting the Google API key. Use a dedicated, restricted Google Custom Search key, avoid sensitive searches, assume queries are sent to Google, and prefer fixing the error handling so raw provider exceptions and URLs are not returned. Pin dependencies or install in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/google_search.py:50
Finding

Google API Key May Be Disclosed Through Raw HTTP Error Messages

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Dependency Versions Create Non-Reproducible and Unsafe Installations

Content
View full analysis
=2.28.0 python-dotenv>=1.0.0 ``` The documented installation procedure executes these unresolved requirements: ```bash pip3 install -r requirements.txt ``` ### Technical Analysis Both dependencies specify only minimum versions. Pip may therefore install any newer release that satisfies the requirement, including versions that were not reviewed or tested by the project maintainers. This makes installations non-reproducible and increases supply-chain exposure. The same source revision can resolve to different dependency versions depending on installation time, package index state, local caches, and resolver behavior. No evidence indicates that the currently named packages are malicious or that dependency confusion is presently occurring. The issue is the absence of controls that constrain installation to reviewed artifacts. ### Attack Path 1. A user follows the documented installation command. 2. Pip contacts the configured package index and resolves the newest releases satisfying the minimum-version constraints. 3. A future compromised, malicious, or incompatible release satisfies those constraints. 4. Pip downloads and installs that release without requiring a project change or additional review. 5. Package installation behavior or imported runtime code executes in the user's environment with the privileges of the account running pip or the application. Successful exploitation depends on an unsafe matching release becoming available through the package source used by the installer. ### Impact Assessment A compromised dependency can potentially execute arbitrary Python code with the privileges of the user performing installation or running the skill. It could access environment variables, including `GOOGLE_API_KEY` and `GOOGLE_CX`, read files available ...[truncated 370 chars]
Remediation
View remediation
python-dotenv== ``` 2. Generate and commit a lock file appropriate for the selected dependency-management workflow. 3. Use cryptographic hashes for production installation, for example through a hash-locked requirements file and pip's `--require-hashes` option. 4. Ensure transitive dependencies are also locked, rather than pinning only the two direct dependencies. 5. Install packages from a trusted, explicitly configured package index and avoid fallback to untrusted indexes. 6. Use automated dependency scanning and controlled update tooling. Review, test, and regenerate hashes before accepting dependency updates. 7. Perform installation inside an isolated virtual environment or container under a non-privileged account. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

3. Configure API Keys

bash
# Get API keys from Google Cloud
export GOOGLE_API_KEY="your_api_key"
export GOOGLE_CX="your_search_engine_id"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/google_search.py (reported line 14)May include surrounding context.

python
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/google_search.py (reported line 28)May include surrounding context.

python
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/google_search.py (reported line 29)May include surrounding context.

python
from pathlib import Path
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/google_search.py (reported line 15)May include surrounding context.

python
from dotenv import load_dotenv

# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
    load_dotenv(env_path)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

🚀 Installation

1. Clone or Create

bash
cd ~/.openclaw/workspace/skills

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation describes a web search capability but does not clearly disclose that user queries are transmitted to Google's external Custom Search API. This creates a privacy and consent issue because users may provide sensitive prompts without realizing they leave the local environment and are subject to Google's logging, retention, and policy controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level description is presented in Chinese while the rest of the document is largely in English, and the file does not state that the skill is intended only for Chinese-speaking users or provide a language/locale choice. This can violate language/locale policy expectations when users have not opted into that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file presents core descriptive content in Chinese while the rest of the document is primarily in English, but it does not explain the intended language behavior or offer an opt-in choice. This can create a language-policy concern when a skill appears to impose or assume a language without user selection.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower bound only (requests>=2.28.0), which makes builds non-reproducible and allows future installs to resolve to unexpected versions. This increases supply-chain risk and makes it harder to determine whether deployed environments include vulnerable or breaking releases.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
python-dotenv>=1.0.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin an exact version, it is impossible to verify whether the installed version is affected. In this skill context, the file alone does not prove exploitation, but it creates real uncertainty around exposure to known dependency flaws.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is not pinned to a specific release (python-dotenv>=1.0.0), so installations may pull different versions over time. That weakens reproducibility and can silently introduce vulnerable or incompatible package versions into the skill environment.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
python-dotenv>=1.0.0

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

python-dotenv has known advisories, and the unpinned requirement prevents verifying whether deployed installs are vulnerable. This is a supply-chain hygiene issue that becomes more concerning if the skill writes .env files or processes attacker-controlled paths, though that behavior is not shown in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function sends the user-provided query to Google's external API, which discloses potentially sensitive user input to a third party. While this is expected for a web-search skill, the lack of an explicit user-facing notice or consent mechanism creates a privacy issue if users may assume queries are processed locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.