Back to skill

Security audit

XCrawl Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward XCrawl search integration that uses a local API key to send user-directed search requests to XCrawl and return the API response.

Install only if you intend to use XCrawl as an external search provider. Search queries, location/language settings, and the API key-bearing request are sent to XCrawl, and responses are returned raw, so avoid submitting secrets, confidential business data, or sensitive personal information as queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: xcrawl-search
description: Use this skill for XCrawl search tasks, including keyword search request design, location and language controls, result analysis, and follow-up crawl or scrape planning.
allowed-tools: Bash(curl:*) Bash(node:*) Read Write Edit Grep
metadata: {"version":"1.0.2","openclaw":{"skillKey":"xcrawl-search","homepage":"https://www.xcrawl.com/","requires":{"localFiles":["~/.xcrawl/config.json"],"anyBins":["curl","node"]},"apiKeySource":"local_config"}}
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that its default behavior is to pass search requests to XCrawl and return upstream response bodies as-is, but it does not prominently warn that user-provided queries and third-party response data are transmitted to an external service. This creates a real data-handling risk because users may provide sensitive terms or expect local-only processing, and the raw echoing of provider responses can propagate unexpected or unsafe content downstream.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The cURL example reads an API key from local configuration and transmits a search payload to XCrawl over the network. Although this matches the skill's purpose, it still exposes user query data to an external service and normalizes a pattern where local credentials are immediately used in outbound requests without an explicit warning or consent boundary.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

bash
API_KEY="$(node -e "const fs=require('fs');const p=process.env.HOME+'/.xcrawl/config.json';const k=JSON.parse(fs.readFileSync(p,'utf8')).XCRAWL_API_KEY||'';process.stdout.write(k)")"

curl -sS -X POST "https://run.xcrawl.com/v1/search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${API_KEY}" \
  -d '{"query":"AI web crawler API","location":"US","language":"en","limit":20}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This code performs an authenticated POST request to an external endpoint using a locally stored API key and sends user-controlled query content off-host. In context this is the intended function of the skill, but it is still a genuine external-transmission risk because sensitive search terms or regulated data could be exfiltrated to a third party, and the response is then returned raw.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
const fs=require("fs");
const apiKey=JSON.parse(fs.readFileSync(process.env.HOME+"/.xcrawl/config.json","utf8")).XCRAWL_API_KEY;
const body={query:"web scraping pricing",location:"DE",language:"de",limit:30};
fetch("https://run.xcrawl.com/v1/search",{
  method:"POST",
  headers:{"Content-Type":"application/json",Authorization:`Bearer ${apiKey}`},
  body:JSON.stringify(body)

Static analysis

No suspicious patterns detected.