T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:1939- Finding
SSRF Protection Can Be Bypassed Through Redirects or DNS Rebinding
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real web search skill, but it needs Review because it stores API keys and search history locally and its SearXNG URL protection can be bypassed in ways that may reach internal network services.
Install only if you are comfortable sending searches to the configured external providers and storing provider keys plus cached query history on disk. Prefer environment variables or a properly permissioned secrets store over config.json for API keys, disable or clear caching for sensitive searches, avoid running the test script against an untrusted .env file, and use a trusted pinned SearXNG deployment rather than arbitrary instance URLs.
scripts/search.py:1939SSRF Protection Can Be Bypassed Through Redirects or DNS Rebinding
test-auto-routing.sh:6Test Script Executes the .env File as Arbitrary Shell Code
scripts/setup.py:405API Credentials Are Stored Without Enforced Restrictive File Permissions
The skill’s declared purpose emphasizes unified search and intelligent auto-routing, but the visible content also includes local configuration, API key handling, and external instance validation behavior not clearly foregrounded in the high-level description. This mismatch can mislead users about what the skill actually does and what data or system capabilities it uses, increasing the risk of unintended exposure or overtrust.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# =============================================================================
def _load_env_file():
"""Load .env file from skill root directory if it exists."""
env_path = Path(__file__).parent.parent / ".env"
if env_path.exists():
with open(env_path) as f:
for line in f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Using source .env executes the contents of the .env file as shell code, not just as data. If an attacker can modify the repository or .env file, arbitrary commands would run when this test script is launched, which turns credential loading into code execution.
# Tests various query types to verify routing works correctly
# Load from environment or .env file
if [ -f .env ]; then
source .env
fi
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences
The FAQ describes local caching of search results but does not warn that cached queries and results may contain sensitive user inputs, URLs, or derived content. On shared systems or poorly secured environments, this can create unintended data retention and local disclosure risks.
The FAQ explicitly recommends storing API keys in config.json without warning that plaintext credentials in configuration files are easier to leak through backups, logs, accidental commits, or local compromise. Because these keys grant access to paid external services, exposure can lead to unauthorized usage and billing abuse.
The FAQ instructs users to run a Docker image without pinning a specific tag or digest, which can cause them to pull an unexpected or later-modified image. This creates supply-chain risk because the image content may change over time and could introduce vulnerable or malicious code into a self-hosted search instance.
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
The JSON API is disabled on your instance. Enable it in `settings.yml` under `search.formats`.
### What's the API cost for SearXNG?
**$0!** SearXNG is free and open-source. You only pay for hosting (~$5/month VPS). Unlimited queries.
### When should I use SearXNG?
- **Privacy-sensitive queries**: No tracking, no profiling
The README promotes automatic routing of user queries to multiple external providers but does not clearly warn that submitted queries may be transmitted to third parties with their own logging, retention, and privacy policies. Users may unknowingly send sensitive internal terms, personal data, or confidential research topics to outside services, increasing privacy and compliance risk.
The README states that search queries and results are automatically cached for one hour in a local .cache/ directory, but it does not warn that cached data may contain sensitive user prompts, proprietary research topics, or personal data. In a shared workstation, CI runner, or multi-user environment, this can lead to unintended retention and disclosure of searchable history and third-party response content.
The skill documentation describes capabilities that require environment access, file read/write, and network access, but it does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, this can cause overbroad execution privileges, making it easier for the skill to access secrets, modify local files, or send data externally without clear user visibility.
The skill markets itself as a simple search interface but does not prominently warn that user queries are transmitted to third-party providers. Queries may contain sensitive business, personal, or internal information, and silent forwarding to multiple external services can create confidentiality and compliance risks.
The documentation instructs users to run a Docker image without a pinned tag or digest, which can pull an unexpected or compromised latest image in the future. This creates a supply-chain risk because the actual code executed is not reproducible or integrity-locked.
No suspicious patterns detected.