Back to skill

Security audit

FlowSearch — Deep Web Research via Claude Native Search

Security checks for vulnerabilities and agentic risk

Overview

FlowSearch does what it says by running Claude for web research, but it also runs Claude with disabled permission checks and the full user environment, which needs careful review before installation.

Install only if you are comfortable with this skill running your local Claude CLI with relaxed permission checks and access to your full shell environment. Prefer reviewing search.ts first, running it in a clean environment containing only the required Claude token, and pinning dependencies before use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
search.ts:77
Finding

Claude CLI Executes Without Permission Checks and Inherits the Entire Parent Environment

Content
View full analysis

Vulnerability Details

File Location: search.ts, lines 77–85
Vulnerability Type: Least-privilege violation and excessive environment exposure
Risk Level: High

Vulnerable Code

typescript
const isRoot = process.getuid?.() === 0;
const args = ["--print", ...(isRoot ? [] : ["--dangerously-skip-permissions"]), "-p", prompt];

return new Promise((resolve) => {
  let output = "";
  let errorOutput = "";

  const proc = spawn(claudePath, args, {
    timeout,
    env: { ...process.env },
    stdio: ["pipe", "pipe", "pipe"],
  });

Technical Analysis

For non-root users, the code starts Claude CLI with --dangerously-skip-permissions. This disables the CLI's normal interactive permission boundaries even though the skill's legitimate purpose only requires web research.

The same subprocess receives a complete copy of process.env. Consequently, the process can access not only the documented CLAUDE_CODE_OAUTH_TOKEN, but also any unrelated credentials, API keys, cloud tokens, database connection strings, or other sensitive values inherited from the parent agent.

This creates a dangerous combination:

  1. The research prompt contains caller-controlled query content.
  2. Web research can introduce untrusted instructions from retrieved pages.
  3. Claude CLI is invoked without its standard permission checks.
  4. The subprocess possesses every inherited environment variable.

Exploitability and the exact resources reachable depend on the tools and capabilities available to the installed Claude CLI. Nevertheless, the implementation unnecessarily removes a security boundary and grants access beyond the stated research task.

Attack Path

  1. An attacker supplies a crafted research query or publishes malicious instructions on a page likely to be returned during research.
  2. The untrusted content is incorporated into or processed during the Claude CLI session.
  3. The skill starts Claude C ...[truncated 1157 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --dangerously-skip-permissions and preserve Claude CLI's normal permission enforcement.

  2. If supported, explicitly allow only the web-search capabilities required by the skill and deny local filesystem, shell, and unrelated network tools.

  3. Replace full environment inheritance with an explicit allowlist, for example:

    typescript
    const childEnv: NodeJS.ProcessEnv = {
      PATH: process.env.PATH,
      HOME: process.env.HOME,
      CLAUDE_CODE_OAUTH_TOKEN: process.env.CLAUDE_CODE_OAUTH_TOKEN,
    };
    
    const proc = spawn(claudePath, ["--print", "-p", prompt], {
      timeout,
      env: childEnv,
      stdio: ["pipe", "pipe", "pipe"],
    });
    
  4. Validate that CLAUDE_CODE_OAUTH_TOKEN exists before execution and avoid passing unrelated environment variables.

  5. Run the subprocess in a sandbox with restricted filesystem and network access.

  6. Clearly separate untrusted query text from trusted instructions and tell the downstream model not to follow instructions embedded in search queries or retrieved pages.

  7. Document the actual subprocess permissions and exposed environment rather than implying that inheritance is limited to the OAuth token.

T08 · Insecure Dependencies

Warning
Location
package.json:8
Finding

Mutable and Unpinned Packages Are Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: package.json, line 8; additionally documented in SKILL.md, lines 39, 45, and 50
Vulnerability Type: Unsafe dependency resolution and runtime package execution
Risk Level: Medium

Vulnerable Code

package.json:

json
"scripts": {
  "search": "npx tsx search.ts"
},
"dependencies": {}

SKILL.md:

bash
npx clawhub@latest install flow-search
bash
npx tsx search.ts "Kling AI pricing 2026"
bash
npx tsx search.ts --deep "AI video generation competitive landscape"

Technical Analysis

The project does not declare tsx as a dependency and provides no lockfile or integrity-pinned dependency graph. When npx tsx is executed and a suitable local binary is unavailable, npx may resolve, download, and execute package code from the configured npm registry.

The installation instructions also explicitly use clawhub@latest. The latest tag is mutable and can resolve to different code over time. Therefore, users following the documented commands may execute code that was not part of this audit.

This is a supply-chain weakness rather than evidence that the current packages are malicious. Exploitation requires compromise or malicious publication of a package/version resolved by these commands, compromise of the configured registry, or manipulation of package resolution.

Attack Path

  1. A user follows the documented installation or execution command.
  2. npx resolves clawhub@latest or an undeclared tsx package through the configured registry.
  3. The resolved package differs from the version expected during review because the tag is mutable, no exact version is declared, or package resolution has been compromised.
  4. npx downloads and executes the package under the invoking user's account.
  5. Malicious package code can access the working directory, user-readable files, inherited environment variables, and net ...[truncated 645 chars]
Remediation
View remediation

Remediation Suggestions

  1. Declare tsx at an exact reviewed version in devDependencies.

  2. Generate and commit a lockfile containing integrity hashes.

  3. Invoke the installed local binary through an npm script instead of using runtime npx resolution:

    json
    {
      "scripts": {
        "search": "tsx search.ts"
      },
      "devDependencies": {
        "tsx": "REVIEWED_EXACT_VERSION"
      }
    }
    
  4. Replace clawhub@latest with an exact, reviewed version.

  5. Use reproducible installation commands such as npm ci and enforce lockfile integrity in CI.

  6. Disable automatic installation prompts for npx in production or agent environments.

  7. Review package provenance, registry configuration, lifecycle scripts, and published checksums before upgrades.

  8. Perform dependency updates through a controlled review process rather than resolving mutable tags during installation or execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
your shell environment to access `CLAUDE_CODE_OAUTH_TOKEN`. Review the source (`search.ts`) before running — it's 150 lines and straightforward.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
your shell environment to access `CLAUDE_CODE_OAUTH_TOKEN`. Review the source (`search.ts`) before running — it's 150 lines and straightforward.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to an environment variable in metadata but does not define an explicit tool/permission scope such as allowed-tools or permissions. Because the skill also spawns a subprocess that inherits the shell environment, the effective capability surface includes secret access and process execution without clear least-privilege boundaries, increasing the chance of unintended token exposure or misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx clawhub@latest install flow-search pulls and executes the latest package version at install time, which is a supply-chain risk. If the upstream package is compromised or a malicious version is published, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documented use of npx tsx search.ts depends on resolving and executing tsx from npm if it is not already installed locally, which can introduce unpinned dependency execution. While this is presented as a convenience command, it still creates a supply-chain exposure path for anyone following the instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The deep research example again relies on npx tsx, repeating the same unpinned package execution risk. In the context of a skill that handles an auth token and launches subprocesses, even documentation-only supply-chain shortcuts are more concerning because successful compromise could expose credentials or alter search behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The script invokes npx tsx without pinning a specific package version, which allows npx to resolve and execute whatever version is available from the registry or local environment at runtime. In an agent skill context, this creates a supply-chain risk: a compromised or unexpected tsx release could be fetched and executed automatically, leading to arbitrary code execution during skill use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file documents use of the CLAUDE_CODE_OAUTH_TOKEN environment variable, and the subprocess is launched with env: { ...process.env }, which forwards that credential to the Claude CLI. While the script states the token is required, it does not clearly warn users that their environment, including authentication data, will be passed into a child process during execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill deliberately adds --dangerously-skip-permissions when not running as root, disabling Claude CLI permission safeguards for the subprocess. Because this skill sends attacker-controlled search/query content into the CLI, relaxing those guardrails increases the chance that prompt-influenced tool actions or data access occur without normal approval boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code launches a subprocess with relaxed permission checks but provides no explicit runtime warning that the child will operate with the user's authenticated Claude context and reduced safeguards. In a research skill that processes arbitrary queries and web content, this makes unsafe behavior more likely and reduces informed consent for operators.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
search.ts:92