T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:104- Finding
Remote Search Queries Can Be Transmitted Over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.py:16,scripts/search.py:104-124; related insecure configuration examples inSKILL.md:125-129,README.md:27-30, andINSTALL.md:85-90
Vulnerability Type: Plaintext transmission of potentially sensitive search queries
Risk Level: MediumVulnerable Code
python # Default to localhost, override with SEARXNG_URL environment variable SEARXNG_URL = os.environ.get('SEARXNG_URL', 'http://127.0.0.1:8080')python params = { 'q': query, 'language': language } if categories: params['categories'] = categories if engines: params['engines'] = engines url = f"{SEARXNG_URL}/search?{urllib.parse.urlencode(params)}" try: headers = { 'User-Agent': 'Mozilla/5.0 (OpenClaw Agent)', 'Accept': 'text/html' } req = urllib.request.Request(url, headers=headers) with urllib.request.urlopen(req, timeout=15) as response:The documentation explicitly permits a remote plaintext endpoint:
bash export SEARXNG_URL=http://your-searxng-instance.com python3 scripts/search.py "query"Technical Analysis
Sending a search query to a SearXNG instance is necessary for the Skill's declared search functionality. However, accepting arbitrary remote
http://endpoints is not necessary and conflicts with the Skill's privacy-focused claims.The query, language, categories, engines, and optional bang are URL-encoded into a GET request. When the configured endpoint uses HTTP, neither confidentiality nor transport integrity is provided. Network intermediaries can inspect or modify the request and response. Because the search terms are placed in the URL, they may also be retained in server, reverse-proxy, gateway, or monitoring logs.
The script does not validate the URL scheme or distinguish loopback endpoints from remote endpoints. It therefore silently accepts inse ...[truncated 1452 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse
SEARXNG_URLwithurllib.parse.urlparsebefore constructing requests. - Require HTTPS whenever the destination is not a loopback address.
- Permit HTTP only for explicitly recognized loopback hosts such as
127.0.0.1,::1, andlocalhost. - Reject unsupported schemes, missing hostnames, URL fragments, and URLs containing embedded credentials.
- Normalize the base URL before appending
/searchto avoid ambiguous URL construction. - Clearly document that a public SearXNG instance receives the user's queries and must be trusted.
- Prefer POST requests where supported to reduce query exposure in URL logs, while recognizing that HTTPS remains necessary.
- Preserve TLS certificate verification and do not add options that disable hostname or certificate validation.
- Consider requiring an explicit opt-in flag before allowing connections to public or non-loopback instances.
- Parse
