Back to skill

Security audit

Serpapi Mcp

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed SerpAPI search wrapper with optional Airtable logging, but users should treat full-result logging and API-key handling as privacy and credential risks.

Install only in an environment where SerpAPI and optional Airtable use are acceptable. Keep Airtable logging off for sensitive or confidential searches unless users explicitly consent, use scoped and revocable tokens, restrict access to the Airtable base, and prefer a pinned/local mcporter install where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a project-local dependency and invoke it through a package script or `npx --no-install` instead of installing it globally. 3. Commit and verify an npm lockfile so transitive dependency versions remain reproducible. 4. Verify the official package name, publisher, registry source, and package integrity before installation. 5. Disable lifecycle scripts during installation where operationally possible: ```bash npm install --ignore-scripts ``` 6. Run third-party tooling with a minimally privileged account and avoid elevated global installation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/serp.sh:64
Finding

SerpAPI Key Exposed Through MCP Endpoint Command Arguments

Content
View full analysis
"$errfile" if mcporter call "$endpoint" --args "$args" --output json > "$tmpfile" 2>"$errfile"; then ``` ### Technical Analysis The SerpAPI key is interpolated directly into the MCP endpoint URL. That URL is then supplied to `mcporter` as a command-line argument. Although the endpoint uses HTTPS and belongs to the documented SerpAPI service, TLS only protects the request while it is in transit. It does not prevent the complete URL from being exposed locally through process inspection, command telemetry, shell or endpoint monitoring, crash reports, or debug output generated by the MCP client. URL paths may also be retained in reverse-proxy and server access logs. Using an API credential as part of a URL therefore expands its exposure beyond the minimum required to authenticate the request. ### Attack Path 1. The Skill reads a SerpAPI credential from `SERPAPI_API_KEY` or `SERPAPI_API_KEYS`. 2. The credential is embedded in the MCP endpoint URL. 3. The complete URL is passed to the `mcporter` child process as an argument. 4. A local process observer, monitoring agent, diagnostic collector, or logging component records the command line or URL. 5. An attacker with access to that record extracts the key. 6. The attacker reuses the key to issue unauthorized SerpAPI requests. ### Impact Assessment A disclosed key could allow unauthorized searches, consumption of the victim's API quota, service disruption through quota exhaustion, and charges associated with the SerpAPI account. The key grants access to the SerpAPI service rather than direct operating-system privileges. The exact account-level scope depends on the permissions and limits assigned t ...[truncated 23 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_ai_overview.mjs:6
Finding

SerpAPI Key and AI Overview Token Embedded in a Query String

Content
View full analysis
"); process.exit(1); } ``` ```javascript const token = data.ai_overview?.token || data.ai_overview_token; if (!token) { // No token found, return original data as-is (maybe AI overview is already there or not triggered). console.log(JSON.stringify(data)); process.exit(0); } const url = `https://serpapi.com/google-ai-overview-api?api_key=${apiKey}&token=${token}&output=json`; ``` The caller supplies the key as follows: ```bash if node "$(dirname "$0")/fetch_ai_overview.mjs" "$used_key" "$tmpfile" > "$enriched_file"; then ``` ### Technical Analysis The script accepts the SerpAPI key through `process.argv` and embeds both the API key and the AI Overview token into an HTTPS query string. Command-line arguments can be visible to local process-inspection and monitoring facilities. Query parameters are additionally likely to be retained by application servers, proxies, gateways, observability platforms, error reports, or URL-level diagnostic logging. HTTPS protects the URL during network transit but does not prevent endpoint or infrastructure logging. The request is directed only to the declared `serpapi.com` service, and fetching the AI Overview is consistent with the Skill's documented functionality. The vulnerability is therefore unsafe credential transport rather than evidence of hidden exfiltration. The static pre-scan reference to the usage message at line 10 does not itself transmit data. The actual exposure occurs when the key is accepted through `process.argv` and inserted into the URL at line 36. ### Attack Path 1. ` ...[truncated 1051 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
*
 * Reads SerpAPI JSON from stdin.
 * Required env:
 *   AIRTABLE_TOKEN      (Personal Access Token)
 *   AIRTABLE_BASE_ID
 *   AIRTABLE_TABLE      (table name or table id)
 * Optional env:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/airtable_log.mjs (reported line 7)May include surrounding context.

js
*
 * Reads SerpAPI JSON from stdin.
 * Required env:
 *   AIRTABLE_TOKEN      (Personal Access Token)
 *   AIRTABLE_BASE_ID
 *   AIRTABLE_TABLE      (table name or table id)
 * Optional env:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents capabilities that use both network access and environment-sourced secrets, but it declares no explicit tool scope or permissions boundary. That creates an authorization and review gap: operators and users cannot easily tell that the skill can reach external services and consume secrets, which increases the chance of unintended data exposure or overbroad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it can optionally persist each query and the full SerpAPI JSON to Airtable, but the user-facing description does not prominently warn that user prompts/searches and returned content may be stored externally. This is dangerous because users may submit personal, regulated, or confidential queries assuming a transient search, while the skill can retain them in a third-party system.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly supports storing raw queries and full response payloads in Airtable, which can include user-supplied sensitive data, third-party content, and potentially regulated or proprietary information in plain text. Persisting full payloads increases the blast radius of any misconfiguration, over-retention, insider access, or compromise of the Airtable workspace.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s stated purpose is logging SerpAPI results, but in the context of a web-search skill it adds persistent exfiltration of search results and metadata into a separate third-party system (Airtable). That exceeds the apparent search-only scope and can expose user queries, returned content, and URLs to an additional service without clear necessity or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This web-search skill uses unrelated Airtable API access and a separate access token, expanding the trust boundary beyond SerpAPI. Even if intended for analytics, introducing a second external integration increases the chance of unauthorized data sharing, policy violations, and accidental leakage of sensitive search content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script forwards the full stdin JSON payload plus derived metadata such as query, engine, URLs, and summary fields to Airtable with no user-facing disclosure or filtering. Because search results may contain sensitive user interests, identifiers, or proprietary content, this creates a meaningful privacy and data-governance risk through silent third-party transmission and storage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code constructs a request to Airtable’s external API, causing search-derived data to leave the local skill environment. In this skill context, that is more dangerous because the skill is expected to perform web searches, not silently replicate user queries and results to an additional third party.

Content

Scanner excerpt · scripts/airtable_log.mjs (reported line 231)May include surrounding context.

js
if (fields[k] === undefined) delete fields[k];
  }

  const url = `https://api.airtable.com/v0/${encodeURIComponent(baseId)}/${encodeURIComponent(table)}`;

  async function getTableSchema() {
    const metaUrl = `https://api.airtable.com/v0/meta/bases/${encodeURIComponent(baseId)}/tables`;

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The schema lookup also contacts Airtable externally using the provided bearer token, confirming that the script performs active network access to a secondary service beyond SerpAPI. While not inherently malicious, it broadens exposure by sending metadata and relying on another external API during execution.

Content

Scanner excerpt · scripts/airtable_log.mjs (reported line 234)May include surrounding context.

js
const url = `https://api.airtable.com/v0/${encodeURIComponent(baseId)}/${encodeURIComponent(table)}`;

  async function getTableSchema() {
    const metaUrl = `https://api.airtable.com/v0/meta/bases/${encodeURIComponent(baseId)}/tables`;
    const resp = await fetch(metaUrl, {
      headers: { Authorization: `Bearer ${token}` },
    });

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script embeds both the SerpAPI API key and the AI overview token directly into the query string. Even over HTTPS, URL query parameters are commonly exposed in logs, process output, monitoring systems, proxies, browser/history equivalents, and upstream infrastructure, which increases the chance of credential leakage. In this skill context, the script is explicitly handling third-party API credentials, so leaking them could enable unauthorized API use or disclosure of request-linked data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script declares optional Airtable logging in comments and later implements persistence of search inputs/results to a third-party service unrelated to the core SerpAPI search function. Even though it is disabled by default, this creates a data exfiltration path for user queries and returned content without any user-facing consent or warning at execution time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This block sends the SerpAPI output and associated query metadata to Airtable when an environment flag is set, which extends the skill from search execution into third-party persistence. Because search terms and results may contain sensitive user data, this behavior can leak information outside the stated purpose and trust boundary of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Search results are optionally transmitted to Airtable based only on environment configuration, with no user-visible warning or confirmation in the script's normal execution path. In an agent skill context, users may reasonably expect web search results to be returned locally, not copied into an external datastore, making this a meaningful privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/airtable_log.mjs:14