Back to skill

Security audit

minimax-web-search

Security checks for vulnerabilities and agentic risk

Overview

This web-search skill is purpose-aligned overall, but it asks users or agents to run mutable third-party code and handle API credentials in ways that need review before installation.

Review this before installing. Use a safer, pinned installation path for uv and minimax-coding-plan-mcp, avoid curl-pipe-to-shell, store the MiniMax API key in a secret manager or tightly permissioned file, and do not run this skill in an environment containing unrelated sensitive environment variables.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:20
Finding

Unverified remote installer is piped directly into a shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-39
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

The installation instructions execute a remotely retrieved, mutable shell script without pinning its version, verifying a checksum, or allowing the user to inspect it first.

bash
**Method 1: Use the official installation script**
curl -LsSf https://astral.sh/uv/install.sh | sh

**Method 2: Use a domestic mirror if the official download fails**

export UV_INDEX_URL="https://pypi.tuna.tsinghua.edu.cn/simple"
curl -LsSf https://astral.sh/uv/install.sh | sh

export UV_INDEX_URL="https://mirrors.aliyun.com/pypi/simple/"
curl -LsSf https://astral.sh/uv/install.sh | sh

Technical Analysis

Piping curl output directly into sh creates a remote code-execution channel. The executed payload is not part of the reviewed Skill package and can change after this audit. HTTPS protects transport under normal conditions but does not establish that the retrieved script is immutable or safe. A compromised upstream server, publishing process, domain, certificate trust path, or delivery infrastructure could replace the installer.

The -f option only rejects HTTP failure responses; it does not validate the content against a trusted digest or signature. The -s option also suppresses progress and some diagnostic information, reducing visibility during installation.

Installing uv is related to the Skill's dependency requirements, but arbitrary remote shell execution is broader than the minimum privilege needed to install a known tool. The script executes with all permissions of the user running the instructions.

Attack Path

  1. An attacker compromises the installer host, its deployment pipeline, or another trusted part of the delivery path.
  2. The attacker modifies https://astral.sh/uv/install.sh to include malicious shell commands.
  3. A user or agent follows the Skill instru ...[truncated 756 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not pipe network content directly into a shell.
  • Prefer installation through an operating-system package manager or another trusted, auditable distribution mechanism.
  • If the upstream installer must be used, download a versioned artifact first, verify a publisher-provided cryptographic signature or a pinned SHA-256 digest, inspect it, and only then execute it.
  • Pin the installer or release version rather than relying on the mutable install.sh endpoint.
  • Run installation as an unprivileged user and explicitly warn users not to use sudo unless a documented step strictly requires it.
  • Avoid presenting alternate package indexes without documenting their trust implications.
  • Example hardened workflow:
bash
curl --proto '=https' --tlsv1.2 -fLo uv-installer.sh \
  'https://example.invalid/pinned-version/uv-installer.sh'
echo 'PINNED_SHA256  uv-installer.sh' | sha256sum --check -
sh uv-installer.sh
rm -f uv-installer.sh

The URL and digest must be replaced with an authentic, version-specific release artifact and checksum obtained through a trusted channel.

T08 · Insecure Dependencies

Error
Location
scripts/web_search.py:53
Finding

Unpinned third-party MCP package is executed through uvx

Content
View full analysis

Vulnerability Details

File Location: scripts/web_search.py:53-60
Vulnerability Type: Insecure dependency execution
Risk Level: High

The runtime invokes a third-party package by name without specifying an exact version or verifying the resolved artifact.

python
proc = subprocess.Popen(
    ['uvx', 'minimax-coding-plan-mcp'],
    stdin=subprocess.PIPE,
    stdout=subprocess.PIPE,
    stderr=subprocess.PIPE,
    env={**os.environ, **env},
    text=True
)

Related installation and usage instructions in SKILL.md:44-61 also refer to the package without a version pin:

bash
uvx minimax-coding-plan-mcp --help
uvx install minimax-coding-plan-mcp

Technical Analysis

uvx resolves and executes the named Python package and its transitive dependencies. Because no exact version or artifact hash is specified, the effective code may change when package-index contents change. The audited Skill therefore delegates local code execution to code that is not included in this repository and is not cryptographically pinned.

The spawned process inherits the parent environment and is explicitly given MINIMAX_API_KEY. It also receives MINIMAX_MCP_BASE_PATH, which points to a user-writable workspace, and can communicate over the network. These capabilities are functionally relevant to the intended MCP search operation, but they significantly increase the impact of a compromised dependency.

No shell is used in this Popen call, so the user-supplied search query does not create direct shell injection here. The principal issue is unpinned supply-chain code execution.

Attack Path

  1. An attacker compromises the publisher account or release pipeline for minimax-coding-plan-mcp, compromises one of its transitive dependencies, or causes the configured package index to serve a malicious release.
  2. The malicious release becomes the version selected by the unpinned uvx invocation.
  3. The u ...[truncated 848 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin minimax-coding-plan-mcp to a reviewed exact version in both documentation and runtime invocation.
  • Lock and verify all transitive dependencies using a lock file with cryptographic hashes.
  • Install dependencies during a controlled setup phase rather than implicitly resolving mutable package-index content during each search.
  • Use a dedicated virtual environment and invoke its verified executable directly.
  • Restrict package indexes to explicitly trusted sources, and avoid switching indexes solely for convenience without equivalent integrity controls.
  • Disable unexpected dependency updates and require a new security review before changing the pinned package or lock file.
  • Construct a minimal child environment rather than merging the complete parent environment. Pass only variables required by the MCP server.
  • Where operationally feasible, sandbox the MCP process with restricted filesystem access and network access limited to the required API endpoint.
  • Ensure diagnostics never print the API key, and rotate the key promptly if dependency compromise is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping curl output to sh creates an immediate command-execution chain from untrusted network content to the local shell. If the fetched content is malicious or tampered with, the attacker gains arbitrary code execution with the privileges of the user running the skill.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

方法 1: 使用官方安装脚本(推荐)

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

方法 2: 使用国内镜像加速(如果官方脚本下载失败)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This command preserves the same dangerous chaining behavior while also modifying the package index environment, potentially confusing provenance and review. The skill context makes it worse because a simple search utility should not silently introduce arbitrary shell execution paths.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

临时使用清华镜像源安装:

bash
export UV_INDEX_URL="https://pypi.tuna.tsinghua.edu.cn/simple"
curl -LsSf https://astral.sh/uv/install.sh | sh

或者临时使用阿里云镜像源:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command again converts a network response directly into shell execution, which is a classic arbitrary-code-execution pattern. Repeating it across fallback paths normalizes unsafe behavior and increases the chance a user or agent will execute it.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

或者临时使用阿里云镜像源:

bash
export UV_INDEX_URL="https://mirrors.aliyun.com/pypi/simple/"
curl -LsSf https://astral.sh/uv/install.sh | sh

1.2 检查 MCP 服务器是否已安装

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Merging the entire os.environ into the subprocess environment is a concrete environment-harvesting issue because it exposes all inherited secrets, tokens, and configuration to an external package execution path. In this skill context, that is more dangerous because the subprocess runs a third-party MCP tool that can access and potentially exfiltrate any forwarded environment variables.

Content

Scanner excerpt · scripts/web_search.py (reported line 67)May include surrounding context.

python
stdin=subprocess.PIPE,
            stdout=subprocess.PIPE,
            stderr=subprocess.PIPE,
            env={**os.environ, **env},
            text=True
        )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands, reads configuration files, accesses environment variables, and performs network operations, but it declares no explicit tool scope or permission boundaries. This increases the chance of over-privileged execution and makes it harder for a runtime or reviewer to constrain risky capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are broad enough to activate on many generic requests for information, increasing the chance the skill runs in contexts where shell setup, package installation, credential handling, or network access were not expected. Broad activation expands the attack surface and raises the likelihood of unintended execution of risky steps.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill runs an MCP server package via uvx without pinning a specific version. This creates a supply-chain risk where a newer or compromised package release could change behavior and execute unreviewed code during skill use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Installing the MCP server with an unpinned uvx install command allows whatever package version is current at execution time to be fetched and run. In a skill that later handles credentials and networked actions, that materially increases supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This mirrored installation path still installs an unpinned MCP package, so using an alternate index does not remove the supply-chain problem. It may additionally expand trust to another repository whose package governance may differ.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The alternate install command repeats the same unpinned package installation pattern. Because this skill is intended for regular web searches, users may execute it often, increasing the attack window for a malicious upstream release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to read and store API credentials from local files and to request secrets from the user, but provides no warning, consent flow, or secure-handling guidance. In combination with shell and file access, this can lead to accidental secret disclosure, insecure storage, or unauthorized credential persistence.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

The skill persists the API key in a plaintext configuration file under the user's home directory, creating long-lived credential exposure if the file permissions are weak, the host is shared, or other tools can read it later. Persistent secrets also increase the blast radius of any later compromise.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

3.3 保存 API Key

bash
mkdir -p ~/.openclaw/config
cat > ~/.openclaw/config/minimax.json << EOF
{
  "api_key": "API密钥",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This skill sends the user's query to an external MiniMax service through an MCP subprocess, but the code itself provides no user-facing disclosure, consent, or filtering. In a search skill, transmitting queries off-host is expected, yet it still creates privacy risk because queries may contain sensitive data that is silently shared with a third party.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/web_search.py (reported line 62)May include surrounding context.

python
]

    try:
        proc = subprocess.Popen(
            ['uvx', 'minimax-coding-plan-mcp'],
            stdin=subprocess.PIPE,
            stdout=subprocess.PIPE,

Tainted flow: 'env' from os.environ.get (line 27, credential/environment) → subprocess.Popen (code execution)

Medium
Category
Data Flow
Confidence
86% confidence
Finding

The subprocess is launched with env={**os.environ, **env}, which forwards the full ambient environment into an external tool. If sensitive or attacker-controlled environment variables are present, they become available to the spawned MCP process, potentially exposing credentials or influencing its behavior in unintended ways.

Content

Scanner excerpt · scripts/web_search.py (reported line 62)May include surrounding context.

python
]

    try:
        proc = subprocess.Popen(
            ['uvx', 'minimax-coding-plan-mcp'],
            stdin=subprocess.PIPE,
            stdout=subprocess.PIPE,

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The skill fetches an external installer script over the network and immediately executes it. This is dangerous because any compromise of the remote host, transport, or script content results in arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

方法 1: 使用官方安装脚本(推荐)

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

方法 2: 使用国内镜像加速(如果官方脚本下载失败)

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

This variant still downloads and executes a remote installer script directly, so changing the package index mirror does not mitigate the core risk. It combines network fetch and code execution in a single step without integrity verification.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

临时使用清华镜像源安装:

bash
export UV_INDEX_URL="https://pypi.tuna.tsinghua.edu.cn/simple"
curl -LsSf https://astral.sh/uv/install.sh | sh

或者临时使用阿里云镜像源:

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The alternate mirrored command repeats the same direct remote script execution pattern. Because the skill is framed as a routine web-search helper, users may not expect such high-risk installation behavior in this context.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

或者临时使用阿里云镜像源:

bash
export UV_INDEX_URL="https://mirrors.aliyun.com/pypi/simple/"
curl -LsSf https://astral.sh/uv/install.sh | sh

1.2 检查 MCP 服务器是否已安装

Static analysis

No suspicious patterns detected.