Back to skill

Security audit

Cstcloud Web Search

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward CSTCloud search wrapper that sends search terms and the configured API key to the documented provider, with install hygiene as the main caution.

Install this only if you are comfortable sending your search queries to CSTCloud and storing a CSTCloud API key in your OpenClaw environment. Avoid searching for secrets or confidential internal text, and prefer a verified or pinned clawhub installer under a non-administrative account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned npm Package Execution in Installation Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and requires shell-capable dependencies (bash, curl, jq) and provides executable command examples, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this weakens least-privilege controls and can let the skill invoke broader shell functionality than users or platform policy expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrase "帮我搜 xxx" is broad and overlaps with ordinary conversation, making accidental or contextually inappropriate invocation more likely. In an agent setting, ambiguous activation can cause unintended outbound requests, disclosure of sensitive user text to the search API, or tool use when the user only meant casual discussion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The installation instruction uses npx clawhub without pinning an exact version, which makes installs dependent on whatever package version is current at execution time. This creates a supply-chain risk: a compromised or incompatible upstream release could be fetched and run automatically in the user's environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This script performs an outbound HTTPS request containing the user's query and bearer token to a remote service. In the context of an agent skill, external transmission is security-relevant because it can exfiltrate sensitive prompts or internal data if users treat the tool as a general assistant capability rather than a third-party network call.

Content

Scanner excerpt · scripts/cstcloud-web-search.sh (reported line 31)May include surrounding context.

sh
exit 1
fi

response=$(curl -s --connect-timeout 30 -X POST "$ENDPOINT" \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg model "$MODEL" --arg query "$QUERY" --argjson count "$COUNT" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the user-provided search query to an external third-party API, but it does not clearly warn the user at runtime that their input will leave the local environment. This matters because search terms may contain sensitive internal, personal, or confidential information, and users invoking a generic 'search' skill may not realize the exact provider receiving the data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language description repeatedly frames the skill as intended for domestic Chinese users and emphasizes avoiding foreign APIs, but it does not offer language or locale choice. This can be interpreted as a locale-specific constraint without an explicit user opt-in or clearly documented compliance justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Several user-visible messages are only in Chinese, while others are in English, which can make the skill unusable or confusing for users who do not read Chinese. The file does not provide any language selection, opt-in, or justification for enforcing this locale behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.