Back to skill

Security audit

MySearch

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent search skill that sends configured queries and API keys to configured search providers or a trusted proxy, with no evidence of hidden persistence, destructive behavior, or remote code execution.

Install only if you trust the publisher and any proxy endpoint you configure. Prefer OpenClaw skill env injection over .env files, do not store production tokens in the skill directory, and use HTTPS trusted provider or proxy URLs because the runtime will send your queries and configured API keys to those endpoints.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
runtime/mysearch/clients.py:2755
Finding

API Credentials Can Be Transmitted to Arbitrary Non-TLS Endpoints

Content
View full analysis
str: return url.rstrip("/") def _provider_base_url( *, explicit_names: tuple[str, ...], proxy_base_url: str, default: str, ) -> str: explicit = _get_str(*explicit_names) if explicit: return _normalize_base_url(explicit) if proxy_base_url: return _normalize_base_url(proxy_base_url) return _normalize_base_url(default) ``` ```python # runtime/mysearch/clients.py:2755-2789 def _request_json( self, *, provider: ProviderConfig, method: str, path: str, payload: dict[str, Any], key: str, base_url: str | None = None, timeout_seconds: int | None = None, ) -> dict[str, Any]: headers: dict[str, str] = {} body = dict(payload) if provider.auth_mode == "bearer": token = key if not provider.auth_scheme else f"{provider.auth_scheme} {key}" headers[provider.auth_header] = token elif provider.auth_mode == "body": body[provider.auth_field] = key else: raise MySearchError(f"unsupported auth mode for {provider.name}: {provider.auth_mode}") url = f"{(base_url or provider.base_url)}{path}" headers.setdefault("Content-Type", "application/json") headers.setdefault("User-Agent", "MySearch/0.2") request_body = json.dumps(body).encode("utf-8") request = Request( url, data=request_body, headers=headers, method=method.upper(), ) try: with urlopen( request, timeout=timeout_seconds or self.config.timeout_seconds, ) as response: status_code = response.status response_text = respo ...[truncated 2782 chars]
Remediation
View remediation
str: parsed = urlparse(url) if parsed.username or parsed.password: raise MySearchError("endpoint URLs must not contain credentials") if not parsed.hostname: raise MySearchError("endpoint URL must contain a hostname") loopback_names = {"localhost", "127.0.0.1", "::1"} if parsed.scheme != "https": if parsed.scheme != "http" or parsed.hostname.lower() not in loopback_names: raise MySearchError( "HTTPS is required for remote credential-bearing endpoints" ) return url.rstrip("/") ``` ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Based on the provided code chunk alone, the implementation does not substantiate the declared search behavior. It contains only package metadata (version) and a docstring, with no logic for calling Tavily, Firecrawl, Exa, X/social search, or any external resources. This is a material mismatch between the declared primary purpose and the actual behavior visible in the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for the operational behavior of a search skill, but the supplied code chunk is an installer script. Its primary purpose is preparing the skill locally by copying files, setting up .env examples, optionally copying secrets, and printing next steps. It explicitly avoids remote downloads and does not execute any search logic or provider aggregation. This is a materially different purpose from the declared search functionality, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- 再回到这个 `SKILL.md` 执行搜索规则和调用策略

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The local debugging example instructs users to copy .env.example to .env inside the working tree. Even though this is common for development, it encourages plaintext secret placement in the repository directory, which can later be copied, backed up, exposed through file-read tooling, or accidentally committed.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

本地调试示例:

bash
cp {baseDir}/.env.example {baseDir}/.env
python3 {baseDir}/scripts/mysearch_openclaw.py health

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 20)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 108)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 111)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 129)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 132)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 135)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 137)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 138)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2720)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2722)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2730)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2731)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2738)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2834)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 2967)May include surrounding context.

python
from urllib.request import Request, urlopen

from mysearch.config import MySearchConfig, ProviderConfig
from mysearch.keyring import MySearchKeyRing


SearchMode = Literal["auto", "web", "news", "social", "docs", "research", "github", "pdf"]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 20)May include surrounding context.

python
label: str


class MySearchKeyRing:
    def __init__(self, config: MySearchConfig) -> None:
        self.config = config
        self._lock = Lock()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 108)May include surrounding context.

python
label: str


class MySearchKeyRing:
    def __init__(self, config: MySearchConfig) -> None:
        self.config = config
        self._lock = Lock()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/clients.py (reported line 111)May include surrounding context.

python
label: str


class MySearchKeyRing:
    def __init__(self, config: MySearchConfig) -> None:
        self.config = config
        self._lock = Lock()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mysearch/keyring.py (reported line 19)May include surrounding context.

python
label: str


class MySearchKeyRing:
    def __init__(self, config: MySearchConfig) -> None:
        self.config = config
        self._lock = Lock()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 116)May include surrounding context.

md
Options:
  --install-to DIR   Copy the skill bundle into DIR before finishing setup
  --copy-env FILE    Copy FILE to target .env with 0600 permissions
                     Optional. Prefer OpenClaw skill env injection instead.
  -h, --help         Show this help

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 246)May include surrounding context.

md
Options:
  --install-to DIR   Copy the skill bundle into DIR before finishing setup
  --copy-env FILE    Copy FILE to target .env with 0600 permissions
                     Optional. Prefer OpenClaw skill env injection instead.
  -h, --help         Show this help

Static analysis

No suspicious patterns detected.