other
- Location
SKILL.md:49- Finding
<![CDATA[Declared privacy controls and private search tool are not implemented]]>
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it makes strong private-search claims that the package does not implement and handles an API key in a weakly disclosed way.
Review this skill carefully before installing. It appears to be a configuration helper and marketing package, not a working private search replacement. Do not rely on its privacy guarantee unless OpenClaw independently provides and verifies the claimed search override. If you run the setup script, expect your Brave key to be shown in the terminal, saved in plaintext, and sent to Brave for a test request; check the target env file permissions and avoid using the generic $HOME/.env for unrelated apps.
SKILL.md:49<![CDATA[Declared privacy controls and private search tool are not implemented]]>
scripts/setup-brave-search.sh:37<![CDATA[Brave API key is visibly collected and stored without enforced restrictive permissions]]>
scripts/setup-brave-search.sh:51<![CDATA[Setup script falls back to modifying the generic home environment file and uses a predictable temporary path]]>
landing-page/index.html:265<![CDATA[Landing page recommends an unpinned global npm installation]]>
npm install -g openclaw && openclaw start. Done.
```
### Technical Analysis
The recommended command installs the current registry-selected version of `openclaw` globally without a version pin, lockfile, package integrity value, or verification of the package publisher. npm packages and their dependencies may execute lifecycle scripts during installation with the privileges of the invoking user.
Because the command uses a mutable package resolution rather than a reviewed version, the effective installed code can change after this Skill has been audited. A compromised package release, registry account, or transitive dependency could consequently execute code on users' systems. A global installation also increases persistence and system-wide exposure compared with a project-local or isolated installation.
The command is documentation rather than automatically executed package code, but it creates a realistic supply-chain risk for users following the landing page.
### Attack Path
1. A user follows the installation instruction on the landing page.
2. npm resolves the currently published package and dependency graph rather than a reviewed, pinned release.
3. A malicious or compromised release contains harmful lifecycle or runtime code.
4. npm executes applicable lifecycle scripts with the invoking user's privileges.
5. The globally installed command remains available and is then started by the user.
6. If the user independently runs the command with elevated privileges, the malicious package may gain correspondingly elevated access.
### Impact Assessment
A compromised package could execute arbitrary code with the privileges of the user runni
...[truncated 382 chars]The documented behavior overstates what the skill actually does, claiming broad private-search routing, engine selection, result-count control, and tracking stripping that static analysis says are not implemented. Security-relevant mismatches are dangerous because users and agents may rely on privacy guarantees that do not exist, causing sensitive search queries to be handled differently than expected.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div class="container">
<!-- HERO -->
<div class="hero">
<div class="news-badge">⚡ Breaking — March 21, 2026</div>
<h1>ChatGPT just added <span>ads</span>.<br>Here's your exit.</h1>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
</div>
<!-- WHAT CHANGED -->
<div class="section">
<h2>What just happened</h2>
<div class="news-quote">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
</div>
<!-- SKILL PROMO -->
<div class="skill-card">
<div class="emoji">🔍</div>
<h3>Private Search for OpenClaw</h3>
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo ""
# Detect OpenClaw config location
CONFIG_FILE="$HOME/.openclaw/.env"
if [ ! -f "$CONFIG_FILE" ]; then
CONFIG_FILE="$HOME/.env"
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo ""
# Detect OpenClaw config location
CONFIG_FILE="$HOME/.openclaw/.env"
if [ ! -f "$CONFIG_FILE" ]; then
CONFIG_FILE="$HOME/.env"
fi
The skill advertises a shell-based setup action (bash scripts/setup-brave-search.sh) while declaring no explicit tool scope or allowed-tools. In an agent ecosystem, undeclared shell capability increases the chance that the agent can invoke command execution unexpectedly, reducing policy transparency and making review and containment harder.
The usage section suggests the skill should activate for ordinary, generic web-search requests, which creates an overly broad trigger surface. In agent systems, broad activation can hijack normal workflows, cause unintended external requests, and increase the chance that sensitive prompts or queries are routed through this skill without clear user intent.
The landing page collects email addresses for a marketing funnel that is unrelated to the stated private-search skill functionality. In this context, the mismatch is risky because the skill is marketed as privacy-preserving while the page solicits personal contact data without clear necessity, creating a trust and data-minimization problem.
The form requests an email address without adequately warning users how the address will be processed, stored, or shared. Because the surrounding page heavily emphasizes privacy and anti-tracking claims, the lack of transparent notice is more dangerous: users may disclose contact information under a false sense of privacy.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -H "Authorization: Bot $KAGI_API_KEY" \
"https://kagi.com/api/v0/search?q=your+query&limit=5"
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo " https://api.search.brave.com/"
echo ""
echo " - Create a free account"
echo " - Go to API Keys → Create Key"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo " https://api.search.brave.com/"
echo ""
echo " - Create a free account"
echo " - Go to API Keys → Create Key"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo " https://api.search.brave.com/"
echo ""
echo " - Create a free account"
echo " - Go to API Keys → Create Key"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo " https://api.search.brave.com/"
echo ""
echo " - Create a free account"
echo " - Go to API Keys → Create Key"
The script prompts for a Brave API key and writes it directly into a .env file without warning the user that the credential will be stored in plaintext. Plaintext secrets in home-directory env files are commonly exposed through weak file permissions, backups, shell tooling, accidental commits, or local compromise, so this creates a real credential-handling weakness even if it is intended for convenience.
The script sends the user-provided API key to Brave's external service in an HTTP header to test connectivity. Although this is functionally necessary for API validation, it is still an external transmission of a credential to a third party, and combined with the script's purpose it is more dangerous because the tool is specifically about privacy-sensitive search routing.
response=$(curl -sf -H "Accept: application/json" \
-H "Accept-Encoding: gzip" \
-H "X-Subscription-Token: $brave_key" \
"https://api.search.brave.com/res/v1/web/search?q=test+query+openclaw&count=1" 2>&1)
if echo "$response" | grep -q '"results"'; then
echo "✅ Brave Search API is working!"
The document declares lang="en", and all user-facing content is written only in English, with no indication that language selection is optional or that the page is intentionally limited to an English-only audience. The stated policy requires flagging natural-language locale constraints when a specific language is imposed without opt-in or justification.
The comment explicitly documents intended behavior of submitting email addresses to external mailing-list services such as ConvertKit or Mailchimp. The actual code shown does not perform that POST and instead only writes the email to the browser console and replaces the form HTML, creating a direct intent/code mismatch in the file's inline documentation.
No suspicious patterns detected.