Back to skill

Security audit

web-scraping

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward web-scraping integration that sends requested public URLs and searches to superagnt's API, with no hidden persistence or local system changes found.

Install this only if you are comfortable sending target URLs, search terms, scrape options, and resulting web-content processing requests to superagnt. Use public, non-sensitive targets unless you have approval to share the target information with that provider, and protect the SUPERAGNT_API_KEY like any other paid API credential.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends user-provided URLs, search queries, and potentially scraped page targets to a third-party service, but it does not clearly warn users about that data flow or advise against submitting sensitive/internal targets. This can lead to unintended disclosure of browsing targets, research topics, or internal URLs to the external provider.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
One call proves the key, the credit balance, and this source end to end:

```bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'
```
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Example

```bash
curl -X POST 'https://api.superagnt.com/v1/data/web/scrape' \
  -H 'Authorization: Bearer your_api_key_here' \
  -H 'Content-Type: application/json' \
  -d '{"url": "https://example.com", "formats": ["markdown"]}'
Confidence
90% confidence
Finding
This finding duplicates the example call that posts data to the external scraping API. The risk is not malicious behavior but insufficient disclosure that user inputs and fetched content may be processed by a third party, which can create privacy and compliance exposure.

External Transmission

Medium
Category
Data Exfiltration
Content
## Example

```bash
curl -X POST 'https://api.superagnt.com/v1/data/web/scrape' \
  -H 'Authorization: Bearer your_api_key_here' \
  -H 'Content-Type: application/json' \
  -d '{"url": "https://example.com", "formats": ["markdown"]}'
Confidence
90% confidence
Finding
This finding duplicates the example call that posts data to the external scraping API. The risk is not malicious behavior but insufficient disclosure that user inputs and fetched content may be processed by a third party, which can create privacy and compliance exposure.

Static analysis

No suspicious patterns detected.