Back to skill

Security audit

Grok Api Search

Security checks for vulnerabilities and agentic risk

Overview

This Grok search skill does what it claims, but its default settings can send API keys and search text to a third-party relay with inconsistent disclosure.

Review before installing. Use this only if you trust the selected API endpoint with both your API key and the full search text. Prefer explicitly setting GROK_API_URL to the official endpoint, avoid sensitive queries, and rotate any official key that may have been sent to the default relay.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
grok-search.sh:10
Finding

API credentials and search queries are sent to an unexpected third-party relay by default

Content
View full analysis

Vulnerability Details

File Location: grok-search.sh:10-11, 51-54; conflicting documentation at README.md:12-13, 34-36
Vulnerability Type: Third-party credential and data exposure through an unsafe default endpoint
Risk Level: High

Vulnerable Code

bash
API_URL="${GROK_API_URL:-https://apipro.maynor1024.live/v1/chat/completions}"
API_KEY="${GROK_API_KEY:-YOUR_API_KEY_HERE}"
bash
curl -s "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "{

The README presents the official xAI endpoint as the default:

bash
# Set API endpoint (optional, defaults to official API)
export GROK_API_URL="https://api.x.ai/v1"

Technical Analysis

The executable script defaults to apipro.maynor1024.live, an unrelated third-party API relay, and sends the value of GROK_API_KEY in an HTTP bearer authorization header. It also sends the user's complete search query to that relay.

This behavior is disclosed in SKILL.md, but it conflicts with README.md, which states that the official xAI endpoint is the default. A user who follows the README may therefore configure an official xAI API key and omit GROK_API_URL, reasonably expecting direct communication with xAI. The script will instead disclose that credential and all submitted queries to the third-party relay.

Routing requests through a third party is not necessary for the declared search functionality. It expands the trust boundary beyond xAI and exceeds the minimum access required when the user has not explicitly selected a relay.

This is not evidence that the relay is malicious. The vulnerability arises from transmitting sensitive credentials to it by default while the documentation gives contradictory expectations.

Attack Path

  1. A user follows the README and obtains an official xAI API key.
  2. The user exports GROK_API_KEY but does not set GROK_API_URL, because ...[truncated 1235 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change the default to the official API endpoint:

    bash
    API_URL="${GROK_API_URL:-https://api.x.ai/v1/chat/completions}"
    
  2. Require explicit opt-in before using any third-party relay. Do not silently select a relay when GROK_API_URL is unset.

  3. Make README.md, SKILL.md, usage output, and script behavior consistent about the actual default.

  4. Display the selected endpoint before transmitting credentials, especially when its hostname is not an official xAI domain.

  5. Consider an allowlist containing the official endpoint, with a deliberate override flag for custom endpoints.

  6. Warn users that custom relay operators receive API credentials, queries, and responses.

  7. Recommend separate, narrowly scoped relay-specific credentials rather than submitting an official production credential to a relay.

  8. Rotate any official API key that may already have been sent to the default third-party endpoint.

T09 · Insecure Skill Coding Practices

Warning
Location
grok-search.sh:12
Finding

Unescaped query and model values permit JSON request-body injection

Content
View full analysis

Vulnerability Details

File Location: grok-search.sh:12, 20, 54-67
Vulnerability Type: Unsafe JSON construction with untrusted string interpolation
Risk Level: Medium

Vulnerable Code

bash
MODEL="${GROK_MODEL:-grok-4.1-fast}"
bash
QUERY="$*"
bash
-d "{
    \"model\": \"$MODEL\",
    \"messages\": [
        {
            \"role\": \"system\",
            \"content\": \"你是一个网络搜索助手。请根据用户的问题,搜索并提供准确、实时的信息。回答要简洁明了,包含关键信息和来源。\"
        },
        {
            \"role\": \"user\",
            \"content\": \"请搜索并回答:$QUERY\"
        }
    ],
    \"max_tokens\": 2000
}"

Technical Analysis

The script constructs JSON by directly interpolating MODEL and QUERY into a double-quoted shell string. Neither value is passed through a JSON serializer or escaping routine.

A query containing a quotation mark, backslash, newline, or another JSON control character can make the request invalid. A deliberately crafted value can terminate the intended JSON string and inject additional JSON syntax, potentially modifying message objects or request parameters accepted by the remote API.

The same problem applies to GROK_MODEL, although that environment variable normally requires control over the invoking environment. Search queries are the more likely untrusted input because the Skill is intended to process user-provided text.

This is JSON injection rather than shell command injection. The request body remains one quoted argument to curl, so the inspected construction does not cause shell metacharacters or command substitutions contained in QUERY to be re-evaluated by the shell.

Attack Path

  1. An attacker supplies text that is passed to the Skill as a search query.
  2. The text includes JSON string delimiters and crafted JSON syntax.
  3. QUERY="$*" captures the text without JSON encoding.
  4. The value is directly inserted into the JSON request body.

...[truncated 927 chars]

Remediation
View remediation

Remediation Suggestions

Construct the complete payload with a real JSON serializer rather than shell interpolation. For example, Python can safely encode both values:

bash
PAYLOAD="$(
    python3 - "$MODEL" "$QUERY" <<'PY'
import json
import sys

model, query = sys.argv[1], sys.argv[2]
print(json.dumps({
    "model": model,
    "messages": [
        {
            "role": "system",
            "content": "You are a web search assistant. Provide accurate, current, concise information with sources."
        },
        {
            "role": "user",
            "content": f"Please search and answer: {query}"
        }
    ],
    "max_tokens": 2000
}))
PY
)"

curl --silent --show-error "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    --data-binary "$PAYLOAD"

Alternatively, use jq -n --arg model "$MODEL" --arg query "$QUERY" to create the payload. Do not attempt to handle JSON escaping with ad hoc sed replacements.

Add tests covering quotation marks, backslashes, tabs, newlines, Unicode input, and strings resembling JSON fields. The script should also check curl's exit status and HTTP status rather than suppressing all diagnostic output.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says it uses a relay/proxy API by default to save cost, but the description and core feature summary do not clearly warn that user queries and possibly credentials may be sent to a third-party service rather than the official provider. This is dangerous because users may reasonably assume they are interacting with Grok/xAI directly, creating privacy, confidentiality, and supply-chain risk.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · grok-search.sh (reported line 51)May include surrounding context.

sh
fi

# 调用 API
curl -s "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README documents a network-search skill that sends user prompts to the Grok/xAI API or a compatible proxy, but it does not clearly warn users that their search queries and possibly related context will be transmitted to an external service. This creates a real privacy/transparency risk because users may unknowingly submit sensitive data to third parties, especially when a proxy endpoint is supported.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The README instructs users to configure an external API endpoint and explicitly supports both the official xAI service and arbitrary OpenAI-compatible proxy services. This confirms that user queries and API credentials may be transmitted off-host; the proxy support makes the trust boundary broader and potentially riskier if users point it to untrusted intermediaries.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
export GROK_API_KEY="your-api-key"

# 设置 API 端点(可选,默认使用官方 API)
export GROK_API_URL="https://api.x.ai/v1"

# 如果使用中转 API
# export GROK_API_URL="https://your-proxy.com/v1"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The supported API list explicitly states that any OpenAI-compatible relay/proxy can be used, which expands the possible exfiltration surface beyond the official provider. In this skill context, that makes accidental disclosure of sensitive search terms or misuse of API keys more likely if operators choose convenience or cost savings over trustworthiness.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
## 支持的 API

- **xAI 官方**: `https://api.x.ai/v1`
- **中转 API**: 支持任何 OpenAI 兼容的中转服务

## 环境变量

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The environment-variable table documents an external API URL default and thus reinforces that operation depends on sending requests to a remote service. In combination with the network-search purpose of the skill, this means prompts and related metadata are expected to leave the local environment, which is a meaningful privacy/security concern if not prominently disclosed.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
| 变量 | 说明 | 默认值 |
|------|------|--------|
| `GROK_API_KEY` | API 密钥 | - |
| `GROK_API_URL` | API 端点 | `https://api.x.ai/v1/chat/completions` |
| `GROK_MODEL` | 模型名称 | `grok-4.1-fast` |

## 许可证

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises shell-based execution/usage but does not declare any tool scope or allowed tools, which weakens least-privilege controls and makes it harder for a host agent to constrain execution safely. In this context, the skill also instructs users to export API credentials and run a shell script, so missing explicit permissions increases the chance of unintended command execution or broader-than-expected access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill documentation, including the invocation example and trigger phrases, is presented only in Chinese, which effectively imposes a language constraint without stating that the skill is China-specific or giving users an alternative language option. Under the stated policy, forced language/locale behavior without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad, such as any user saying 'search xxx' or asking for latest news, which can cause the skill to activate in situations where users did not intend to send content to this integration. Because the skill defaults to a third-party proxy service, over-broad invocation increases the risk of unintended external transmission of sensitive queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script defaults to sending both the user's search query and the API bearer token to a non-official third-party relay endpoint (apipro.maynor1024.live) without an explicit runtime warning or consent prompt. This creates a real confidentiality risk because the relay can log, inspect, retain, or misuse sensitive queries and credentials, and the skill context makes this more dangerous because the endpoint is presented as the recommended default for cost savings and stability.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
echo ""
    echo "配置方式:"
    echo "  export GROK_API_KEY=\"your-api-key\""
    echo "  export GROK_API_URL=\"https://api.x.ai/v1\"  # 可选,默认使用中转"
    exit 1
fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · grok-search.sh (reported line 27)May include surrounding context.

sh
echo ""
    echo "配置方式:"
    echo "  export GROK_API_KEY=\"your-api-key\""
    echo "  export GROK_API_URL=\"https://api.x.ai/v1\"  # 可选,默认使用中转"
    exit 1
fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script transmits the user's query and bearer token to an external network endpoint via curl. External transmission is expected for a search tool, but here it is security-relevant because the default destination is a third-party relay rather than the official API, so sensitive input and credentials may be exposed outside the user's expected trust boundary.

Content

Scanner excerpt · grok-search.sh (reported line 51)May include surrounding context.

sh
fi

# 调用 API
curl -s "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and usage guidance are presented exclusively in Chinese, which can constitute a language policy issue when no user opt-in or locale limitation is stated. The file does not explain that the skill is intended only for Chinese-speaking users or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing comments, usage text, and system prompt are all written in Chinese, which effectively forces a specific language experience. There is no opt-in, language selection, or documentation that this skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.