T09 · Insecure Skill Coding Practices
- Location
src/google_search.py:50- Finding
Google API Key May Be Disclosed Through Raw HTTP Error Messages
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward Google search skill, but it can expose the user's Google API key in error output.
Review this before installing if you care about protecting the Google API key. Use a dedicated, restricted Google Custom Search key, avoid sensitive searches, assume queries are sent to Google, and prefer fixing the error handling so raw provider exceptions and URLs are not returned. Pin dependencies or install in an isolated environment.
src/google_search.py:50Google API Key May Be Disclosed Through Raw HTTP Error Messages
requirements.txt:1Unbounded Dependency Versions Create Non-Reproducible and Unsafe Installations
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Get API keys from Google Cloud
export GOOGLE_API_KEY="your_api_key"
export GOOGLE_CX="your_search_engine_id"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from pathlib import Path
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from dotenv import load_dotenv
# Load environment variables from .env file
env_path = Path(__file__).parent.parent / '.env'
if env_path.exists():
load_dotenv(env_path)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
cd ~/.openclaw/workspace/skills
The documentation describes a web search capability but does not clearly disclose that user queries are transmitted to Google's external Custom Search API. This creates a privacy and consent issue because users may provide sensitive prompts without realizing they leave the local environment and are subject to Google's logging, retention, and policy controls.
The top-level description is presented in Chinese while the rest of the document is largely in English, and the file does not state that the skill is intended only for Chinese-speaking users or provide a language/locale choice. This can violate language/locale policy expectations when users have not opted into that language.
The file presents core descriptive content in Chinese while the rest of the document is primarily in English, but it does not explain the intended language behavior or offer an opt-in choice. This can create a language-policy concern when a skill appears to impose or assume a language without user selection.
The dependency is specified with a lower bound only (requests>=2.28.0), which makes builds non-reproducible and allows future installs to resolve to unexpected versions. This increases supply-chain risk and makes it harder to determine whether deployed environments include vulnerable or breaking releases.
requests>=2.28.0
python-dotenv>=1.0.0
requests has multiple known advisories, and because the manifest does not pin an exact version, it is impossible to verify whether the installed version is affected. In this skill context, the file alone does not prove exploitation, but it creates real uncertainty around exposure to known dependency flaws.
The dependency is not pinned to a specific release (python-dotenv>=1.0.0), so installations may pull different versions over time. That weakens reproducibility and can silently introduce vulnerable or incompatible package versions into the skill environment.
requests>=2.28.0
python-dotenv>=1.0.0
python-dotenv has known advisories, and the unpinned requirement prevents verifying whether deployed installs are vulnerable. This is a supply-chain hygiene issue that becomes more concerning if the skill writes .env files or processes attacker-controlled paths, though that behavior is not shown in this file.
The function sends the user-provided query to Google's external API, which discloses potentially sensitive user input to a third party. While this is expected for a web-search skill, the lack of an explicit user-facing notice or consent mechanism creates a privacy issue if users may assume queries are processed locally.
No suspicious patterns detected.