Back to skill

Security audit

Private Search

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it makes strong private-search claims that the package does not implement and handles an API key in a weakly disclosed way.

Review this skill carefully before installing. It appears to be a configuration helper and marketing package, not a working private search replacement. Do not rely on its privacy guarantee unless OpenClaw independently provides and verifies the claimed search override. If you run the setup script, expect your Brave key to be shown in the terminal, saved in plaintext, and sent to Brave for a test request; check the target env file permissions and avoid using the generic $HOME/.env for unrelated apps.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

other

Error
Location
SKILL.md:49
Finding

<![CDATA[Declared privacy controls and private search tool are not implemented]]>

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-brave-search.sh:37
Finding

<![CDATA[Brave API key is visibly collected and stored without enforced restrictive permissions]]>

Content
View full analysis
"$CONFIG_FILE.tmp" && mv "$CONFIG_FILE.tmp" "$CONFIG_FILE" fi echo "BRAVE_API_KEY=$brave_key" >> "$CONFIG_FILE" ``` The script also discloses an existing key prefix: ```bash if [ -n "$BRAVE_API_KEY" ]; then echo "✅ BRAVE_API_KEY already set in environment." echo " Current key: ${BRAVE_API_KEY:0:8}..." ``` ### Technical Analysis The `read` command does not use silent input, so the full API key is echoed while the user types or pastes it. The script then prints the first eight characters of the supplied key. These values may be exposed through shoulder surfing, terminal recording, shared consoles, support transcripts, or screenshots. The credential is written in plaintext to an environment file. The script neither sets a restrictive `umask` nor applies permissions such as mode `0600`. If the target file is newly created under a common permissive umask, it may be readable by users or processes outside the intended security boundary. Although plaintext environment files may be operationally necessary, displaying the credential and failing to enforce access permissions exceed the minimum exposure needed to configure the Skill. ### Attack ...[truncated 934 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-brave-search.sh:51
Finding

<![CDATA[Setup script falls back to modifying the generic home environment file and uses a predictable temporary path]]>

Content
View full analysis
"$CONFIG_FILE.tmp" && mv "$CONFIG_FILE.tmp" "$CONFIG_FILE" fi echo "BRAVE_API_KEY=$brave_key" >> "$CONFIG_FILE" echo "PRIVATE_SEARCH_ENGINE=brave" >> "$CONFIG_FILE" echo "PRIVATE_SEARCH_STRIP_TRACKING=true" >> "$CONFIG_FILE" ``` ### Technical Analysis If `$HOME/.openclaw/.env` does not already exist, the script selects `$HOME/.env` rather than securely creating the application-specific directory and file. A generic home environment file may be consumed by unrelated applications, development tools, shell plugins, or automation. Writing the Brave key and OpenClaw-specific settings there broadens credential exposure and introduces cross-application configuration side effects. The script also reconstructs an existing file through the predictable path `$CONFIG_FILE.tmp`. It does not use `mktemp`, reject symbolic links, install a cleanup trap, or preserve the original file's metadata explicitly. Redirection follows an existing symbolic link, so an attacker able to create or influence that path in the same writable directory could redirect the temporary write to another file accessible to the victim account. Replacing the original with `mv` may also change its permissions according to the process umask. ### Attack Path 1. The OpenClaw-specific `.env` file does not exist. 2. The setup script falls back to `$HOME/.env`. 3. The script writes the Brave credential and search ...[truncated 1349 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
landing-page/index.html:265
Finding

<![CDATA[Landing page recommends an unpinned global npm installation]]>

Content
View full analysis
One command: npm install -g openclaw && openclaw start. Done.

``` ### Technical Analysis The recommended command installs the current registry-selected version of `openclaw` globally without a version pin, lockfile, package integrity value, or verification of the package publisher. npm packages and their dependencies may execute lifecycle scripts during installation with the privileges of the invoking user. Because the command uses a mutable package resolution rather than a reviewed version, the effective installed code can change after this Skill has been audited. A compromised package release, registry account, or transitive dependency could consequently execute code on users' systems. A global installation also increases persistence and system-wide exposure compared with a project-local or isolated installation. The command is documentation rather than automatically executed package code, but it creates a realistic supply-chain risk for users following the landing page. ### Attack Path 1. A user follows the installation instruction on the landing page. 2. npm resolves the currently published package and dependency graph rather than a reviewed, pinned release. 3. A malicious or compromised release contains harmful lifecycle or runtime code. 4. npm executes applicable lifecycle scripts with the invoking user's privileges. 5. The globally installed command remains available and is then started by the user. 6. If the user independently runs the command with elevated privileges, the malicious package may gain correspondingly elevated access. ### Impact Assessment A compromised package could execute arbitrary code with the privileges of the user runni ...[truncated 382 chars]
Remediation
View remediation
``` - Link users to the verified official package and publisher identity. - Publish checksums, provenance attestations, or npm package signatures where supported. - Recommend reviewing package metadata and lifecycle scripts before installation. - Prefer an isolated, project-local, or containerized installation over a global installation where feasible. - Explicitly warn users not to execute the installation as root or through `sudo`. - Maintain a documented update process so users can intentionally move between reviewed versions rather than automatically receiving a mutable latest release. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior overstates what the skill actually does, claiming broad private-search routing, engine selection, result-count control, and tracking stripping that static analysis says are not implemented. Security-relevant mismatches are dangerous because users and agents may rely on privacy guarantees that do not exist, causing sensitive search queries to be handled differently than expected.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · landing-page/index.html (reported line 211)May include surrounding context.

html
<div class="container">

  <!-- HERO -->
  <div class="hero">
    <div class="news-badge">⚡ Breaking — March 21, 2026</div>
    <h1>ChatGPT just added <span>ads</span>.<br>Here's your exit.</h1>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · landing-page/index.html (reported line 243)May include surrounding context.

html
</div>
  </div>

  <!-- WHAT CHANGED -->
  <div class="section">
    <h2>What just happened</h2>
    <div class="news-quote">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · landing-page/index.html (reported line 292)May include surrounding context.

html
</div>
  </div>

  <!-- SKILL PROMO -->
  <div class="skill-card">
    <div class="emoji">🔍</div>
    <h3>Private Search for OpenClaw</h3>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-brave-search.sh (reported line 51)May include surrounding context.

sh
echo ""

# Detect OpenClaw config location
CONFIG_FILE="$HOME/.openclaw/.env"
if [ ! -f "$CONFIG_FILE" ]; then
  CONFIG_FILE="$HOME/.env"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-brave-search.sh (reported line 53)May include surrounding context.

sh
echo ""

# Detect OpenClaw config location
CONFIG_FILE="$HOME/.openclaw/.env"
if [ ! -f "$CONFIG_FILE" ]; then
  CONFIG_FILE="$HOME/.env"
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises a shell-based setup action (bash scripts/setup-brave-search.sh) while declaring no explicit tool scope or allowed-tools. In an agent ecosystem, undeclared shell capability increases the chance that the agent can invoke command execution unexpectedly, reducing policy transparency and making review and containment harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage section suggests the skill should activate for ordinary, generic web-search requests, which creates an overly broad trigger surface. In agent systems, broad activation can hijack normal workflows, cause unintended external requests, and increase the chance that sensitive prompts or queries are routed through this skill without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The landing page collects email addresses for a marketing funnel that is unrelated to the stated private-search skill functionality. In this context, the mismatch is risky because the skill is marketed as privacy-preserving while the page solicits personal contact data without clear necessity, creating a trust and data-minimization problem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The form requests an email address without adequately warning users how the address will be processed, stored, or shared. Because the surrounding page heavily emphasizes privacy and anti-tracking claims, the lack of transparent notice is more dangerous: users may disclose contact information under a false sense of privacy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/privacy-engines.md (reported line 63)May include surrounding context.

API Example

bash
curl -H "Authorization: Bot $KAGI_API_KEY" \
  "https://kagi.com/api/v0/search?q=your+query&limit=5"

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo "   https://api.search.brave.com/"
echo ""
echo "   - Create a free account"
echo "   - Go to API Keys → Create Key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/privacy-engines.md (reported line 7)May include surrounding context.

md
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo "   https://api.search.brave.com/"
echo ""
echo "   - Create a free account"
echo "   - Go to API Keys → Create Key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/privacy-engines.md (reported line 31)May include surrounding context.

md
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo "   https://api.search.brave.com/"
echo ""
echo "   - Create a free account"
echo "   - Go to API Keys → Create Key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup-brave-search.sh (reported line 31)May include surrounding context.

sh
echo "------------------------------------------"
echo ""
echo "👉 Open this URL in your browser:"
echo "   https://api.search.brave.com/"
echo ""
echo "   - Create a free account"
echo "   - Go to API Keys → Create Key"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script prompts for a Brave API key and writes it directly into a .env file without warning the user that the credential will be stored in plaintext. Plaintext secrets in home-directory env files are commonly exposed through weak file permissions, backups, shell tooling, accidental commits, or local compromise, so this creates a real credential-handling weakness even if it is intended for convenience.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The script sends the user-provided API key to Brave's external service in an HTTP header to test connectivity. Although this is functionally necessary for API validation, it is still an external transmission of a credential to a third party, and combined with the script's purpose it is more dangerous because the tool is specifically about privacy-sensitive search routing.

Content

Scanner excerpt · scripts/setup-brave-search.sh (reported line 81)May include surrounding context.

sh
response=$(curl -sf -H "Accept: application/json" \
  -H "Accept-Encoding: gzip" \
  -H "X-Subscription-Token: $brave_key" \
  "https://api.search.brave.com/res/v1/web/search?q=test+query+openclaw&count=1" 2>&1)

if echo "$response" | grep -q '"results"'; then
  echo "✅ Brave Search API is working!"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document declares lang="en", and all user-facing content is written only in English, with no indication that language selection is optional or that the page is intentionally limited to an English-only audience. The stated policy requires flagging natural-language locale constraints when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment explicitly documents intended behavior of submitting email addresses to external mailing-list services such as ConvertKit or Mailchimp. The actual code shown does not perform that POST and instead only writes the email to the browser console and replaces the form HTML, creating a direct intent/code mismatch in the file's inline documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.