T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/tavily_search.py:27- Finding
Automatic Access to a Shared Credential File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Tavily web-search skill, but it automatically reads a local shared credential file in a way that is not clearly disclosed.
Install only if you are comfortable sending search queries to Tavily and allowing the helper to use a Tavily API key. Prefer setting TAVILY_API_KEY directly in the runtime environment; avoid relying on ~/.openclaw/.env unless you understand that the script opens that local secret file.
scripts/tavily_search.py:27Automatic Access to a Shared Credential File
This code accesses a local .env file under the user's home directory to retrieve credentials. Reading local secret files expands the skill's trust boundary and can expose credentials through unintended access patterns, especially in agent environments where skills should not browse arbitrary local secrets for convenience.
if key:
return key.strip()
env_path = pathlib.Path.home() / ".openclaw" / ".env"
if env_path.exists():
try:
txt = env_path.read_text(encoding="utf-8", errors="ignore")
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if not key:
raise SystemExit(
"Missing TAVILY_API_KEY. Set env var TAVILY_API_KEY "
"or add it to ~/.openclaw/.env"
)
payload["api_key"] = key
data = json.dumps(payload).encode("utf-8")
The skill documents and implies use of environment variables, local script execution, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent platform may expose the skill more broadly than intended, making it harder to enforce least privilege and increasing the risk of unintended data access or external exfiltration through the search API.
The description says the skill should be used whenever the agent needs to search the web, get news, find answers, or look up sources, which is broad enough to match many common user requests. Overly broad invocation criteria can cause the agent to route sensitive or unnecessary queries to this external-search skill by default, increasing privacy leakage and unintended network use.
The markdown advertises search and Q&A features but does not warn users that submitted queries are sent to the external Tavily API. This creates a real data exposure risk because users or upstream agents may pass sensitive prompts, identifiers, or proprietary research terms to a third-party service without informed consent.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import sys
import urllib.request
TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import sys
import urllib.request
TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import sys
import urllib.request
TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import sys
import urllib.request
TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import sys
import urllib.request
TAVILY_SEARCH_URL = "https://api.tavily.com/search"
TAVILY_NEWS_URL = "https://api.tavily.com/news"
TAVILY_QNA_URL = "https://api.tavily.com/qna"
TAVILY_IMAGES_URL = "https://api.tavily.com/images"
The skill reads credentials from a local ~/.openclaw/.env file in addition to the process environment. That grants filesystem access to local secrets beyond what is strictly required for a web-search helper and increases the chance of unintended credential harvesting or reuse if the skill is repurposed or compromised.
The markdown formatter emits the fixed label "相关话题" for related topics, which enforces a specific language in output regardless of user preference or locale. The file does not provide any language selection or document that the skill is intentionally region-specific.
No suspicious patterns detected.