Back to skill

Security audit

cn-ai-search

Security checks for vulnerabilities and agentic risk

Overview

This search skill is mostly a Chinese web-search CLI, but it ships hard-coded third-party API keys and under-discloses how queries are routed through external services.

Install only after the publisher removes and rotates the bundled Tavily and Jina keys, documents which external services receive queries, and preferably pins dependencies. Treat any searches as shared with Jina and the selected search providers; avoid sensitive or proprietary queries unless you have reviewed and replaced the credentials with your own.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
config.py:9
Finding

Hard-Coded Third-Party API Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned and Unverified Python Dependencies

Content
View full analysis
=2.31.0 beautifulsoup4>=4.12.0 pydantic>=2.0.0 click>=8.0.0 ``` The documented installation procedure installs whatever versions satisfy these open-ended constraints: ```bash pip install -r requirements.txt ``` ### Technical Analysis Each dependency specifies only a minimum version and has no upper bound, exact version, or package hash. Consequently, the code reviewed during this audit is not sufficient to determine the code that a future installation will execute or import. The listed package names are standard PyPI projects, and the audit found no evidence that any currently referenced package is malicious. The risk arises from unresolved future versions and transitive dependencies. A compromised upstream release, malicious transitive dependency, incompatible major release, or unauthorized package-index response could be selected without any modification to this Skill. Depending on the artifact selected by pip, package code may execute during source builds, through build-system hooks, or later when imported by the application. Hashless installation also prevents pip from detecting whether the downloaded artifact differs from the artifact reviewed by the project maintainer. ### Attack Path 1. An attacker compromises an upstream dependency, its publishing account, or a transitive dependency. 2. The attacker publishes a malicious release whose version satisfies the project’s `>=` constraint. 3. A user follows the documented `pip install -r requirements.txt` procedure. 4. Pip resolves the malicious version because no exact version or trusted hash restricts selection. 5. Malicious code executes during package building, installation, or subsequent import under the privileges of the user perfo ...[truncated 946 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A description-behavior mismatch is a real security issue here because the declared purpose is simple aggregated search, while the detected implementation reportedly includes hardcoded third-party API credentials, an external AI summarization service, and additional web-fetching through Jina Reader that are not disclosed. Undocumented external services and embedded secrets can cause data exfiltration, unauthorized billing, secret leakage, and trust-boundary violations for users who believe they are only invoking local or direct search functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises AI summarization via Tavily but does not disclose that user queries and possibly aggregated search results may be transmitted to a third-party service. In an agent/search skill, users may submit sensitive prompts, internal research topics, or proprietary data, so this omission creates a real privacy and data-handling risk rather than a purely documentation issue.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and enables network-based search behavior but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this weakens policy enforcement and transparency, making it easier for the skill to perform outbound requests without clear operator awareness or sandbox constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and title explicitly position the skill as '中文AI Agent专用' and '中文AI聚合搜索', indicating a fixed language/locale constraint in the natural-language description. Because the file does not offer any user choice, opt-in, or explain a justified region-specific compliance need, this is a language/locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language comments describe the skill as a Chinese AI aggregate search configuration and present the setup entirely in Chinese without indicating that users may choose another language or locale. This can be a language/locale policy issue when the skill appears to force a specific language experience without opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains hard-coded third-party API credentials for Tavily and Jina. Embedded secrets are a real security issue because anyone with access to the skill source can reuse the keys, incur cost, access associated service quotas/data, and potentially pivot into other connected systems depending on the provider account configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI defaults and hardcoded supported platforms constrain searches to Chinese-language and China-centric services without explicit user opt-in, which can bias results, reduce coverage, and route user queries to region-specific third parties. In an agent context, this can silently shape downstream decisions or expose sensitive search terms to a narrower geopolitical and provider set than the user may expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description states this is a "中文AI Agent专用" tool, which indicates the skill is intended specifically for Chinese-language AI agents and does not offer a user language choice. This is a natural-language locale policy concern because it imposes a language constraint without documenting opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README presents the skill as Chinese-only and all user-facing documentation is in Chinese, but it does not explicitly offer language/locale choice or justify the restriction as a region-specific requirement. Under the policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency declaration uses a lower-bound specifier (requests>=2.31.0) instead of pinning an exact version, which makes builds non-reproducible and can cause installation of unexpected future releases or vulnerable intermediary versions depending on resolution behavior. In a network-facing search tool, this increases supply-chain uncertainty because requests is directly used for outbound HTTP interactions and has had multiple security advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
beautifulsoup4>=4.12.0
pydantic>=2.0.0
click>=8.0.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The manifest does not pin the requests version, so it is impossible to verify from this file whether the installed release avoids known requests advisories. This is especially relevant here because the skill is a multi-platform search tool and likely relies on HTTP requests extensively, increasing exposure if a vulnerable version is resolved at install time.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

beautifulsoup4 is unpinned, so installations may vary over time and across environments, reducing reproducibility and making it harder to verify whether deployed versions are secure and tested. While this library is less directly security-sensitive than an HTTP client, unexpected parser behavior changes can still affect the robustness of a scraping/search aggregation tool.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
beautifulsoup4>=4.12.0
pydantic>=2.0.0
click>=8.0.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

pydantic>=2.0.0 allows a wide range of versions to be installed, which prevents assurance about exactly which code is running and whether known vulnerable releases are excluded. Because pydantic often processes external or user-controlled input, version ambiguity can matter when parser or validation bugs are disclosed.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
beautifulsoup4>=4.12.0
pydantic>=2.0.0
click>=8.0.0

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Because pydantic is not pinned, the requirements file does not establish whether deployed environments will use a version affected by known pydantic CVEs. Since pydantic commonly validates untrusted input, ambiguity around the installed version creates avoidable uncertainty in a component that may process external search parameters or structured responses.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

click is specified as click>=8.0.0, which permits installation of many versions, including potentially vulnerable ones, and prevents reproducible builds. For an agent skill that may expose CLI entry points or wrapper scripts, dependency ambiguity can broaden supply-chain risk even if no direct exploit is shown in this file.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests>=2.31.0
beautifulsoup4>=4.12.0
pydantic>=2.0.0
click>=8.0.0

Unverifiable Dependency: click has 1 known advisory(ies) (CVE-2026-7246 (Pallets Click, versions 8.3.2 and below, contain a command injection vulnerabili)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The click dependency is unpinned, so the file does not prove that an installed version is free from known advisories. If the skill exposes command-line operations, an inadvertently resolved vulnerable click release could introduce avoidable risk through dependency drift.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.