Back to skill

Security audit

Free Web Search Js

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real web search/fetch tool, but it can fetch arbitrary HTTP URLs from the agent runtime and runs untrusted pages in Chromium with the browser sandbox disabled.

Install only in an isolated environment with restricted network access if you use it. Avoid giving it internal, localhost, cloud metadata, or private-network URLs, and prefer explicit --region plus --no-fetch when privacy matters. Consider updating Playwright and removing the default no-sandbox browser flags before using it on sensitive hosts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch.js:200
Finding

Arbitrary URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
a.startsWith('http')); ``` ### Technical Analysis The fetch command accepts an arbitrary string beginning with `http` and sends a request to it through either the Node.js Fetch API or Chromium. It does not validate the URL protocol using a URL parser, resolve and inspect the destination address, or reject loopback, link-local, private, reserved, and cloud metadata address ranges. The HTTP implementation also uses `redirect: 'follow'`. Consequently, validating only the original URL would remain insufficient because a public endpoint could redirect the request to a protected internal destination. The Playwright fallback is affected independently because `page.goto()` can navigate directly to internal HTTP services. This functionality requires access to user-selected public web pages, but unrestricted access to destinations visible from the Agent host exceeds that requirement. ### Attack Path 1. An attacker causes the Agent to invoke the fetch tool with an internal URL, such as a loopback service, private-network host, or cloud instance metadata endpoint. 2. Alternatively, the attacker provides an apparently public URL that redirects to an internal address. 3. `scripts/fetch.js` accepts the URL because it begins with `http`. 4. The lightweight HTTP tier follows the destination and an ...[truncated 944 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/playwright-support.js:11
Finding

Chromium Sandbox Is Disabled for Untrusted Web Content

Content
View full analysis
Remediation
View remediation

other

Note
Location
scripts/search.js:65
Finding

Automatic Region Detection Discloses the Runtime Public IP to Multiple Third Parties

Content
View full analysis
{ for (const url of ['https://myip.ipip.net', 'https://cip.cc']) { try { const r = await fetch(url, { headers: { 'User-Agent': UA }, signal: AbortSignal.timeout(3000) }); if (!r.ok) continue; const text = await r.text(); if (/中国|CN/i.test(text)) { const ip = text.match(/(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})/)?.[1] ?? '?'; return { inChina: true, label: `${ip} → CN` }; } } catch {} } throw new Error('cn probe failed'); })(), (async () => { for (const url of ['https://ipinfo.io/json', 'https://ipapi.co/json/']) { try { const r = await fetch(url, { headers: { 'User-Agent': UA }, signal: AbortSignal.timeout(3000) }); if (!r.ok) continue; const d = await r.json(); const cc = String(d.country || d.country_code || '').toUpperCase(); if (!cc) continue; return { inChina: cc === 'CN', label: `${d.ip ?? '?'} → ${cc}` }; } catch {} } throw new Error('intl probe failed'); })(), (async () => { const r = await fetch('https://cn.bing.com', { headers: { 'User-Agent': UA }, signal: AbortSignal.timeout(3000), redirect: 'manual' }); return { inChina: r.status === 200 || r.status === 302, label: `cn.bing.com → ${r.status}` }; })(), ]; ``` ### Technical Analysis When the region option remains at its default automatic setting, the Skill starts three probe groups concurrently. Requests are sent to IPIP, CIP, IPinfo, IPapi, and Bing depending on availability and timing. Each contacted service necessarily receives the Agent host's public source IP and request metadata. The behavior is disclosed in `SKILL.md`, and no hidden telemetry or credential transmission was found. Nev ...[truncated 1204 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/setup.sh:42
Finding

Installation Can Retrieve Dependencies and Chromium from a Third-Party Mirror

Content
View full analysis
/dev/null)"; then if echo "$resp" | grep -qi "中国\|CN"; then IN_CHINA=true break fi fi done NPM_REGISTRY_ARG="" if [ "$IN_CHINA" = true ]; then echo "[OK] 国内网络,使用 npmmirror 镜像" export PLAYWRIGHT_DOWNLOAD_HOST="https://npmmirror.com/mirrors/playwright" NPM_REGISTRY_ARG="--registry=https://registry.npmmirror.com" else echo "[OK] 海外网络,使用官方源" fi echo "" echo "Installing npm packages..." cd "$SKILL_ROOT" if [ -n "$NPM_REGISTRY_ARG" ]; then npm install $NPM_REGISTRY_ARG else npm install fi ``` The Windows setup script implements the same behavior at `scripts/setup.ps1:44-73`. The lockfile records `registry.npmmirror.com` as the resolved source for dependencies throughout `package-lock.json`. ### Technical Analysis When network detection identifies the environment as being in China, setup automatically changes both the npm registry and Playwright browser download host to `npmmirror.com`. This adds a third-party distribution service to the dependency trust chain. The npm lockfile contains integrity hashes, which reduce the opportunity to substitute altered npm package archives without detection. However, the installation process still relies on the mirror's availability and correct artifact delivery, and browser-download verification depends on Playwright's own mechanisms. The setup uses `npm install` rather than the more reproducible `npm ci`. No malicious or typosquatted dependency was identified in the reviewed manifest. The risk arises from automatic selection of an additional artifact source rather than from confirmed malicious pac ...[truncated 1218 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (53)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Very broad trigger keywords like 'search', 'find', and common Chinese equivalents are likely to activate in ordinary conversation, causing unintended invocation of a network-enabled skill. In this skill's context, accidental activation can leak user queries to third-party search engines and initiate external browsing/fetching without clear user intent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
script: scripts/fetch.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
script: scripts/fetch.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
script: scripts/fetch.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
node scripts/check-env.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
node scripts/check-env.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
node scripts/check-env.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
node scripts/check-env.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
node scripts/check-env.js

Known Vulnerable Dependency: playwright==1.52.0 — 1 advisory(ies): CVE-2025-59288 (Playwright downloads and installs browsers without verifying the authenticity of)

High
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins playwright to 1.52.0, and the reported advisory indicates browser downloads/installations may occur without authenticity verification. In a skill whose purpose is automated web access via Playwright, that is materially relevant: if browser binaries are fetched during setup or update from a compromised mirror or intercepted path, the environment could install and execute tampered browser code.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: playwright==1.52.0 — 1 advisory(ies): CVE-2025-59288 (Playwright downloads and installs browsers without verifying the authenticity of)

High
Category
Supply Chain
Confidence
93% confidence
Finding

The package depends on Playwright 1.52.0, which is flagged for CVE-2025-59288 involving browser downloads/installations without authenticity verification. In this skill's context, that risk is more significant because the package explicitly uses Playwright for browser automation, increasing exposure to compromised browser binaries or tampered installation artifacts during setup or updates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises automatic fetching of search-result pages and later documents region detection via external IP-probing services, but it does not clearly warn users that queries, target URLs, and client IP/network metadata may be disclosed to third parties. In a search/fetch skill, this context makes the omission more serious because network activity is core behavior and may surprise users operating in sensitive or restricted environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes capabilities that imply network, environment, and shell-adjacent execution without declaring an explicit permission boundary in the manifest. That increases the chance a host agent invokes it with broader authority than intended, reducing reviewability and making misuse of external connectivity or local execution paths harder to constrain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatically choosing region behavior based on IP/location without opt-in can disclose network/location characteristics to third-party probe services and alter search routing in ways the user did not request. Because this skill performs multiple outbound probes and search requests, the privacy impact is amplified and can expose user environment details during routine use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using npx playwright without pinning an exact version allows the resolved package/version to vary over time, which introduces supply-chain risk and undermines reproducibility. If a malicious or compromised upstream version is fetched, users may execute attacker-controlled code during install or runtime preparation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code issues outbound HTTP requests to arbitrary URLs and sends request metadata such as the User-Agent and Accept-Language headers. It also retrieves and returns page content, but the file does not contain a docstring, comment, or user-facing warning explaining that external sites will be contacted and their content processed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.