Back to skill

Security audit

Openclaw Web Search Mcp

Security checks for vulnerabilities and agentic risk

Overview

This web research skill matches its stated purpose, but unsafe URL handling and a YouTube transcript command bug could let it reach internal network resources or run local commands.

Review before installing. Use only in a sandboxed environment with restricted network egress and trusted callers until the publisher replaces shell execSync with argument-based execution, validates URLs and YouTube IDs, blocks private/internal destinations, adds time and size limits, removes committed debug output, and updates vulnerable dependencies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
extraction/youtubeTranscript.js:69
Finding

OS Command Injection Through the YouTube Transcript URL

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
extraction/pageExtractor.js:4
Finding

Server-Side Request Forgery in Page and Link Extraction

Content
View full analysis
{ const href=$(e).attr("href"); const text=$(e).text(); if(href) links.push({text,url:href}); }); return links.slice(0,50); } ``` The functions are directly reachable through `index.js:19-23`: ```js if (tool === "open_page") return console.log(JSON.stringify(await extractPage(input.url))); if (tool === "extract_links") return console.log(JSON.stringify(await extractLinks(input.url))); ``` ### Technical Analysis Both functions pass a caller-controlled URL directly to Axios. The code does not validate: - URL schemes. - Destination hostnames or ports. - Resolved IP addresses. - Loopback, private, link-local, multicast, or otherwise reserved address ranges. - Redirect destinations. - DNS rebinding conditions. Axios follows redirects by default. Consequently, even an initially public hostname can redirect the request to an internal destination unless every redirect target is independently validated. Because the fetched HTML is parsed and portions of it are returned to the caller, this behavior can expose response data from services that are reachable from the MCP host but not directly reachable by an external attacker. ### Attack Path 1. An attacker invokes `open_page` or `extract_links`. 2. The attacker supplies a URL targeting a loopback address, private ...[truncated 846 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
extraction/pdfExtractor.js:4
Finding

Server-Side Request Forgery in PDF Extraction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
extraction/pdfExtractor.js:4
Finding

Unbounded Remote Content Download and Parsing Enables Denial of Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
extraction/youtubeTranscript.js:63
Finding

Predictable Shared Subtitle File Creates Race and Symlink Risks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
output.txt:96
Finding

Committed Debug Transcript Discloses Operational Environment Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

No manifest is available, so there is no declared purpose that would justify granting a skill arbitrary subprocess execution. The observed behavior runs yt-dlp through the shell against user-controlled input, which is a materially broader capability than simple in-process data handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

The lockfile pins axios 1.13.6, and the provided advisories include SSRF, prototype-pollution-assisted MITM/credential theft, and related request handling flaws. In a browser/web-fetching MCP skill, HTTP client behavior is security-relevant, so a vulnerable axios version materially increases risk if the skill fetches attacker-controlled URLs or honors proxy environment settings.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names/filenames. If the skill constructs multipart requests using attacker-influenced values, this can corrupt request structure or inject unintended headers/content toward upstream services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.22.0 — 16 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +13 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

undici 7.22.0 is flagged for multiple HTTP parsing and smuggling issues, including request/response smuggling and CRLF-related problems. Because cheerio depends on undici and this skill appears to perform network retrieval/parsing, these flaws can affect interactions with attacker-controlled endpoints or intermediaries.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The package manifest permits installation of axios 1.13.6, and the static analysis indicates that version has multiple known advisories including SSRF-related and prototype-pollution/MITM exploitation paths. In a skill described as a web-search or browsing MCP for agents, HTTP client behavior is security-critical because the component likely fetches attacker-controlled URLs and remote content, making known axios flaws materially more dangerous in context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill explicitly provides web search, page fetching, PDF extraction, YouTube transcript retrieval, and automated research, but the description does not warn users that it will access external network resources and process untrusted third-party content. That omission can cause users or downstream agents to invoke the skill without understanding privacy, data exposure, or prompt-injection risks from remote content, which is especially relevant for a research-oriented MCP.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Both extractPage and extractLinks perform server-side HTTP requests directly to a caller-supplied URL with no validation, allowlist, or protocol restrictions. This creates an SSRF-style primitive that can be used to make the host access internal services, cloud metadata endpoints, or other unintended network targets; the scraping context increases risk because fetching arbitrary pages is the core behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function performs an HTTP request to a caller-supplied URL and downloads remote content, which can transmit user-provided data and interact with external systems. There is no confirmation prompt, logging, comment, or docstring disclosing this network behavior in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command forces transcript extraction to English via --sub-lang en, and the surrounding comment explicitly states 'only English'. This imposes a language choice without any indication of user selection, opt-in, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

With no manifest available, the skill's stated purpose is unknown, so spawning a local binary is not justified by any declared intent. The code uses execSync to run yt-dlp, which is a materially more powerful capability than simple in-process text parsing and can have broader system effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function interpolates a user-supplied URL directly into a shell command passed to execSync, which creates a command injection risk if quoting can be broken or shell metacharacters are interpreted unexpectedly. It also allows undisclosed network-capable subprocess execution against attacker-controlled input, increasing the blast radius to arbitrary command execution or unwanted outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This text file contains executable Node.js commands that invoke execSync to run yt-dlp, which triggers shell execution and network access to YouTube. Although runtime warnings from yt-dlp are shown later, there is no user-facing comment, prompt, or explanatory note in the file itself disclosing that a shell command will contact an external service and process subtitle output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language-facing behavior here constrains subtitle retrieval to English by specifying --sub-lang en, and the later invocation appears to do the same transcript operation for the user without offering a language choice. That creates a locale policy issue because the skill behavior fixes the language rather than letting the user choose or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
82% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. In a tool that may retrieve remote resources, this can expose bearer tokens or API keys when an attacker controls a redirect target, especially because axios depends on this package.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: mongoose==8.23.0 — 1 advisory(ies): CVE-2026-73562 (Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed )

Low
Category
Supply Chain
Confidence
70% confidence
Finding

mongoose 8.23.0 is flagged for prototype pollution in update casting via proto-prefixed properties. This is a real issue in environments that pass attacker-controlled update objects into Mongoose, though the skill’s declared top-level dependencies do not directly indicate active database use, so exploitability in this specific context is less certain.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==9.0.1 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
61% confidence
Finding

uuid 9.0.1 is flagged for a missing bounds check in certain hash-based UUID variants when a caller supplies a buffer. This appears real, but impact is limited unless the application explicitly uses v3/v5/v6 APIs with attacker-controlled buffer arguments; no such usage is visible from the lockfile alone.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"main": "index.js",
  "type": "commonjs",
  "dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0",
    "natural": "^6.5.0",
    "p-limit": "^4.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"type": "commonjs",
  "dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0",
    "natural": "^6.5.0",
    "p-limit": "^4.0.0",
    "pdf-parse": "^1.1.1",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0",
    "natural": "^6.5.0",
    "p-limit": "^4.0.0",
    "pdf-parse": "^1.1.1",
    "youtube-transcript": "^1.2.1"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"axios": "^1.6.0",
    "cheerio": "^1.0.0",
    "natural": "^6.5.0",
    "p-limit": "^4.0.0",
    "pdf-parse": "^1.1.1",
    "youtube-transcript": "^1.2.1"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"cheerio": "^1.0.0",
    "natural": "^6.5.0",
    "p-limit": "^4.0.0",
    "pdf-parse": "^1.1.1",
    "youtube-transcript": "^1.2.1"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"natural": "^6.5.0",
    "p-limit": "^4.0.0",
    "pdf-parse": "^1.1.1",
    "youtube-transcript": "^1.2.1"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code performs a network request using axios and sends request metadata, including a User-Agent header, but the file contains no comment, docstring, log, or prompt disclosing that outbound network access occurs. For code files, network calls that transmit user or system data should have some visible warning unless clearly covered by the skill's stated purpose, which is not evident in this file alone.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
extraction/youtubeTranscript.js:69