Back to skill

Security audit

proxy-web-search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed web-search proxy wrapper; it sends search queries to a configured OpenClaw Manager proxy and shows no hidden persistence, credential theft, or destructive behavior.

Install only if you trust the configured OpenClaw Manager Web Search Proxy. Do not submit secrets, credentials, private incident details, or proprietary terms as search queries unless that proxy is approved for that data, and prefer a trusted HTTPS WEB_SEARCH_PROXY_URL.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code generally matches the core declared purpose: it routes web search requests through a proxy configured by WEB_SEARCH_PROXY_URL, defaults to Quark, supports other listed engines, and allows time-range filtering and result count. However, the description claims support for filtering by domain and controlling detail level, but the script exposes no domain parameter and no detail-level parameter or related behavior. Because these are user-visible advertised capabilities that are absent from the implementation, this is a description-behavior mismatch, though the primary purpose remains aligned.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell via curl but does not declare any tool scope such as permissions or allowed-tools. This weakens policy enforcement and review because consumers cannot clearly see or restrict that the skill performs network-capable shell execution, increasing the chance of unintended command or network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill transmits user search queries and related parameters to an external proxy, but it does not present a clear user-facing warning about that data disclosure. Users may submit sensitive internal terms, incident details, credentials, or proprietary research under the assumption of local processing, causing confidentiality and privacy exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This skill performs intentional outbound network transmission of arbitrary user-provided search content to a proxy endpoint defined by an environment variable. In context this is expected functionality, but it still creates a real data-exfiltration surface because the destination may be external or misconfigured, and the proxy handles potentially sensitive queries.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Quick Start

Basic cURL Usage

bash
curl --request POST \

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This code performs external transmission of user-controlled query content to a URL fully determined by the WEB_SEARCH_PROXY_URL environment variable, with no validation of the endpoint. That means sensitive search content can be exfiltrated to an unintended or attacker-controlled service if the environment is misconfigured or manipulated, and the 'no auth needed' design further reduces safeguards around where data is sent.

Content

Scanner excerpt · scripts/proxy_search.sh (reported line 60)May include surrounding context.

sh
# Build JSON payload
PAYLOAD="{\"search_query\": \"$SAFE_QUERY\", \"search_engine\": \"$ENGINE\", \"search_intent\": $INTENT, \"count\": $COUNT, \"search_recency_filter\": \"$RECENCY\"}"

# Execute cURL request to Web Search Proxy (no auth needed)
curl -s --request POST \
  --url "${PROXY_URL}/" \
  --header "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the user's raw search query and parameters to an external proxy service without any runtime disclosure, confirmation, or indication of where the data is going. In a tool explicitly acting as a 'proxy', this creates a real privacy and data-handling risk because sensitive prompts, internal research topics, or proprietary terms may be transmitted off-host unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.