Back to skill

Security audit

联网搜索一键配置 · Tavily One-Step

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Tavily web-search skill, but its install instructions ask the agent to persistently change future search behavior and clone mutable code from GitHub.

Review before installing. The Tavily API key requirement is normal for this kind of search skill, but avoid adding the persistent memory preference unless you explicitly want future general searches routed through Tavily. Prefer installing from a pinned commit or verified release, and keep the API key only in a trusted local environment file.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
README.md:21
Finding

Installation Instructions Require Persistent Agent Memory Modification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:16
Finding

Installation Uses an Unpinned Mutable Git Repository

Content
View full analysis
Remediation
View remediation
``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

md
1) Target directory must be: ~/.openclaw/workspace/skills/tavily-search
2) Clone source: https://github.com/plabzzxx/openclaw-tavily-search
3) Ensure script exists at: ~/.openclaw/workspace/skills/tavily-search/scripts/tavily_search.mjs
4) Create ~/.openclaw/.env if missing, and ensure this placeholder line exists:
   TAVILY_API_KEY=
5) Run the checks silently. Do NOT dump detailed path-by-path logs unless user asks.
6) Add a memory preference:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tavily_search.mjs (reported line 10)May include surrounding context.

js
function loadKey() {
  if (process.env.TAVILY_API_KEY?.trim()) return process.env.TAVILY_API_KEY.trim();
  const envPath = path.join(os.homedir(), ".openclaw", ".env");
  if (!fs.existsSync(envPath)) return null;
  const txt = fs.readFileSync(envPath, "utf8");
  const m = txt.match(/^\s*TAVILY_API_KEY\s*=\s*(.+?)\s*$/m);

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The install prompt directs the agent to create persistent state in two places: a long-lived .env file for the API key placeholder and a memory preference that changes future tool-selection behavior. Persistent modifications are security-relevant because they survive the current session, can influence later agent actions without renewed consent, and the instruction to run checks silently reduces transparency around those changes.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

md
1) Target directory must be: ~/.openclaw/workspace/skills/tavily-search
2) Clone source: https://github.com/plabzzxx/openclaw-tavily-search
3) Ensure script exists at: ~/.openclaw/workspace/skills/tavily-search/scripts/tavily_search.mjs
4) Create ~/.openclaw/.env if missing, and ensure this placeholder line exists:
   TAVILY_API_KEY=
5) Run the checks silently. Do NOT dump detailed path-by-path logs unless user asks.
6) Add a memory preference:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents capabilities that require network access and use of environment-based secrets, but the manifest declares no explicit tool scope or permissions. This creates a transparency and governance gap: an orchestrator or reviewer may approve the skill as lower-risk than it really is, increasing the chance of unintended network access or secret exposure during use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill primarily as simple web search, while the documented CLI also supports full-page extraction, crawling, and URL mapping. This scope expansion matters because crawling and extraction can collect substantially more data from external sites than users may expect, enabling overbroad data retrieval or policy bypass under the guise of search.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a web search tool, but it also exposes extract, crawl, and map operations against arbitrary URLs and sites. This expands the capability surface beyond the declared purpose and can enable broader remote content collection or site enumeration without users realizing it, which is especially risky in agent environments where tool descriptions influence trust and invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description contains both Chinese and English text but does not indicate whether the skill supports language selection or respects the user's preferred locale. Per the policy, forcing or assuming a language/locale without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents handling of a sensitive credential (TAVILY_API_KEY) by placing it in an environment variable or ~/.openclaw/.env. While this is expected configuration, the description provides no user-facing warning about protecting the key or avoiding accidental exposure in shared environments.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/tavily_search.mjs:9