Back to skill

Security audit

Openclaw Search Pro

Security checks for vulnerabilities and agentic risk

Overview

This search skill is mostly purpose-aligned, but its URL extraction and documentation create real review-worthy privacy and internal-network risk.

Install only if you are comfortable with search queries and extracted URLs being sent to external providers. Avoid using URL extraction on untrusted links in sensitive networks, prefer environment variables for API keys, and review or update the npm dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract.js:76
Finding

SSRF Protection Bypass Through Redirects, DNS Rebinding, and Incomplete IP Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract.js:120
Finding

Unbounded Response Buffering Enables Memory Exhaustion

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package-lock.json:24
Finding

Dependency Lockfile Uses a Third-Party Registry Mirror

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios 1.13.6, and the static analysis indicates multiple published advisories including SSRF/proxy-bypass and prototype-pollution-related request manipulation issues. In a search aggregation skill that makes outbound HTTP requests to multiple engines and likely processes user-controlled URLs or queries, a vulnerable HTTP client materially increases risk of SSRF, credential leakage, or traffic interception effects.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
85% confidence
Finding

form-data 4.0.5 is reported as vulnerable to CRLF injection via unescaped multipart field names and filenames. If this skill ever constructs multipart requests using user-influenced field names or filenames—for example when interacting with optional APIs or upload-style endpoints—an attacker could manipulate request structure or smuggle unexpected headers/content.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.4 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

undici 7.24.4 is flagged with multiple high-severity advisories including response queue poisoning, information disclosure, and desynchronization issues. Because this package is brought in through cheerio and may be used for network fetching in a tool that retrieves arbitrary web content, these flaws can affect confidentiality and integrity of fetched results, especially under attacker-controlled server responses.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification for axios permits installation of vulnerable versions, and the finding indicates a resolved version selection that includes known SSRF and related security advisories. Because this skill is a multi-engine search tool making outbound web requests and likely handling untrusted URLs/content, an HTTP client weakness is especially relevant and can enable request manipulation, proxy bypass, or exposure of internal resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide tells users to place long-lived API credentials directly into a local JSON config file, but does not warn about file permissions, accidental commits, backups, or other forms of secret exposure. In a developer tool skill, this is a real secret-handling weakness because users commonly store skill directories in synced folders or version control, making credential leakage plausible.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to run python3 search-pro/scripts/*.py, which expands to every Python script in the directory and can execute unintended files. Combined with the vague guidance to 'check scripts/ directory', this weakens execution boundaries and increases the chance of running helper, test, or maliciously added scripts without understanding their behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file advertises web search, multi-engine aggregation, and URL content extraction, but the security notes claim 'No network calls (unless specified)' and 'No data sent to external servers'. For a search skill, these statements are materially misleading because the core function necessarily involves outbound requests and possible transmission of search queries, URLs, and extracted content to third-party services, which can cause unsafe operator assumptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises and documents network access and reading a local configuration file, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance and review gap: downstream systems or users may not realize the skill requires network and file-read capabilities, increasing the risk of unintended data exposure or over-privileged execution.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
**注意:** API Key 存储在 `config/search-config.json`,没有单独的 api-keys.json 文件

**安全建议:**
- 配置文件权限:`chmod 600 config/search-config.json`
- 不要将 API Key 提交到 Git(添加到 .gitignore)
- 使用环境变量更安全(不写入文件)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/baidu_search.py (reported line 106)May include surrounding context.

python
'bs': 0  # 起始位置
            }
            
            response = requests.post(url, headers=headers, json=payload, timeout=10)
            response.raise_for_status()
            
            data = response.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends the user's search query to Baidu's cloud API, but this request path does not provide any user-facing notice, consent flow, or sensitivity check before transmitting potentially private input to a third party. In a search/research skill, users may enter confidential terms, making silent external transmission a real privacy risk rather than a purely theoretical issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The fallback path transmits user queries to Baidu mobile web search without an explicit warning, so data may leave the system even when the official API path fails. Because this is an automatic fallback, users may not realize their input is being sent to a different third-party endpoint, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file's title, class docstrings, inline usage text, comments, and CLI output are written in Chinese, with no indication that users can choose another language. This can violate language/locale policy when a skill imposes a single language by default rather than offering an opt-in or alternative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code sends user search queries directly to third-party services including DuckDuckGo, Bing, Google, and Tavily, but provides no disclosure, consent flow, or data-handling notice to the caller. This can expose sensitive prompts, internal project names, credentials pasted into queries, or regulated data to external providers, which is a real privacy and data-governance risk in an agent skill.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.obfuscated_code

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/axios/dist/node/axios.cjs:3533

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/axios/lib/adapters/http.js:605

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/undici/lib/dispatcher/socks5-proxy-agent.js:59

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/entities/lib/esm/generated/decode-data-html.js:4

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/entities/lib/generated/decode-data-html.js:6

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/parse5/node_modules/entities/dist/commonjs/generated/decode-data-html.js:7

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/parse5/node_modules/entities/dist/esm/generated/decode-data-html.js:4

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
node_modules/parse5/node_modules/entities/src/generated/decode-data-html.ts:5