Back to skill

Security audit

Openclaw Tavily Search

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tavily web-search skill, but it automatically reads a local shared credential file in a way that is not clearly disclosed.

Install only if you are comfortable sending search queries to Tavily and allowing the helper to use a Tavily API key. Prefer setting TAVILY_API_KEY directly in the runtime environment; avoid relying on ~/.openclaw/.env unless you understand that the script opens that local secret file.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/tavily_search.py:27
Finding

Automatic Access to a Shared Credential File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This code accesses a local .env file under the user's home directory to retrieve credentials. Reading local secret files expands the skill's trust boundary and can expose credentials through unintended access patterns, especially in agent environments where skills should not browse arbitrary local secrets for convenience.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 29)May include surrounding context.

python
if key:
        return key.strip()

    env_path = pathlib.Path.home() / ".openclaw" / ".env"
    if env_path.exists():
        try:
            txt = env_path.read_text(encoding="utf-8", errors="ignore")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 58)May include surrounding context.

python
if not key:
        raise SystemExit(
            "Missing TAVILY_API_KEY. Set env var TAVILY_API_KEY "
            "or add it to ~/.openclaw/.env"
        )
    payload["api_key"] = key
    data = json.dumps(payload).encode("utf-8")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents and implies use of environment variables, local script execution, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent platform may expose the skill more broadly than intended, making it harder to enforce least privilege and increasing the risk of unintended data access or external exfiltration through the search API.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says the skill should be used whenever the agent needs to search the web, get news, find answers, or look up sources, which is broad enough to match many common user requests. Overly broad invocation criteria can cause the agent to route sensitive or unnecessary queries to this external-search skill by default, increasing privacy leakage and unintended network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown advertises search and Q&A features but does not warn users that submitted queries are sent to the external Tavily API. This creates a real data exposure risk because users or upstream agents may pass sensitive prompts, identifiers, or proprietary research terms to a third-party service without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 14)May include surrounding context.

python
import sys
import urllib.request

TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 15)May include surrounding context.

python
import sys
import urllib.request

TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 16)May include surrounding context.

python
import sys
import urllib.request

TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 17)May include surrounding context.

python
import sys
import urllib.request

TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily_search.py (reported line 18)May include surrounding context.

python
import sys
import urllib.request

TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill reads credentials from a local ~/.openclaw/.env file in addition to the process environment. That grants filesystem access to local secrets beyond what is strictly required for a web-search helper and increases the chance of unintended credential harvesting or reuse if the skill is repurposed or compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown formatter emits the fixed label "相关话题" for related topics, which enforces a specific language in output regardless of user preference or locale. The file does not provide any language selection or document that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.