Back to skill

Security audit

Huo15 Searxng

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but its Docker deployment and persistent configuration changes are broad enough that users should review them before installing.

Install only if you are comfortable with a persistent Docker SearXNG container, a SEARXNG_BASE_URL entry being written to ~/.zshrc, and a local port being exposed through Docker. Prefer pinning the SearXNG image, binding the port to 127.0.0.1, and avoiding the README curl-to-shell Docker install command.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:143
Finding

Unverified Remote Installer Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:113
Finding

Automatically Executed Container Image Uses a Mutable Latest Tag

Content
View full analysis
"$DOCKER_DIR/docker-compose.yml" << EOF services: searxng: image: searxng/searxng:latest container_name: searxng restart: unless-stopped ``` ```bash start_searxng() { log_info "启动 SearXNG 容器..." cd "$DOCKER_DIR" # 停止旧容器(如果存在) if docker ps -a 2>/dev/null | grep -q "searxng$"; then log_info "停止旧容器..." docker compose down --remove-orphans 2>/dev/null || true fi docker compose up -d --pull always ``` ### Technical Analysis The generated Compose configuration references `searxng/searxng:latest`, which is a mutable image tag. The installer then uses `--pull always`, ensuring that current registry content is downloaded and executed whenever deployment reaches this step. As a result, the effective executable payload is not fixed to the version reviewed during this audit. The image namespace is consistent with the declared SearXNG dependency, and no evidence of dependency confusion or typosquatting was found. Nevertheless, a compromised publisher account, registry, build pipeline, or mutable tag can silently replace the image used by future installations. The container applies `cap_drop: ALL` and `no-new-privileges:true`, which reduce runtime privilege, but they do not eliminate access to mounted writable configuration and data directories, the published network service, or outbound network connectivity. ### Attack Path 1. An attacker compromises the upstream image publication process or registry account. 2. The attacker replaces the image referenced by `searxng/searxng:latest`. 3. A user invokes the installation or upgrade workflow. 4. `docker compose up -d --pull always` retrieves the changed image. 5. Docker starts the unreviewed payload as a persistent container. 6. The payload can access wr ...[truncated 727 chars]
Remediation
View remediation
@sha256: ``` - Remove `--pull always` from ordinary installation and status workflows. - Implement upgrades as a separate, explicit operation that: 1. Identifies the proposed version and digest. 2. Verifies image provenance or signatures. 3. Presents the change to the user. 4. Requires confirmation before replacing the running image. - Use registry signature verification or an equivalent supply-chain control where supported. - Retain the existing capability drop and `no-new-privileges` protections. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:119
Finding

Local SearXNG Service Is Published on All Host Network Interfaces

Content
View full analysis
` and only requires local OpenClaw access. Publishing on external host interfaces therefore exceeds the minimum network privileges needed for the stated functionality. The generated configuration enables HTML and JSON search formats, while no authentication layer is configured. Although Docker capability restrictions harden the container process, they do not prevent remote clients from reaching the published application endpoint. ### Attack Path 1. The Skill deploys SearXNG using a mapping such as `8888:8080`. 2. Docker binds host port 8888, or another selected port through 8910, on all available host interfaces. 3. A remote system with network access to the host connects to that port. 4. The remote client accesses the SearXNG interface or JSON endpoint. 5. The client submits searches or repeatedly invokes endpoints to consume service and outbound network resources. Exploitation depends on host firewall rules and network reachability, but the Skill unnecessarily creates the listening exposure. ### Impact Assessment Reachable attackers may use the host as an unintended search proxy, consume CPU, mem ...[truncated 346 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/env.sh:7
Finding

Shell Profile Assignments Are Parsed with Broad Grep and Unsafe Word Splitting

Content
View full analysis
/dev/null || true fi # 默认值 SEARXNG_BASE_URL="${SEARXNG_BASE_URL:-http://localhost:8888}" ``` `scripts/status.sh`: ```bash # 加载环境变量 if [ -f "$HOME/.zshrc" ]; then export $(grep "SEARXNG_BASE_URL" "$HOME/.zshrc" 2>/dev/null | grep -v '^#' | xargs) 2>/dev/null || true fi ``` ### Technical Analysis Both scripts select profile lines containing the text `SEARXNG_BASE_URL`, process those lines with `xargs`, and then pass the resulting words as arguments to the shell `export` builtin. This is not a safe parser for shell syntax. Matching is not restricted to the exact assignment generated by the installer, and `xargs` changes quoting, whitespace, and argument boundaries. Multiple matching lines can also be merged into one invocation. Consequently, unrelated or malformed profile content can cause unintended variables or values to be imported into the script environment. No direct arbitrary command execution was confirmed from these exact statements because the command substitution output becomes arguments to the `export` builtin rather than being re-evaluated as shell program text. The primary confirmed risk is environment manipulation and unreliable endpoint selection. ### Attack Path 1. `~/.zshrc` contains a malformed, duplicated, or unrelated line containing `SEARXNG_BASE_URL`. 2. The broad `grep` expression selects that line. 3. `xargs` removes or rewrites quoting and splits the content into words. 4. `export` receives unintended assignments or identifiers. 5. The environment or status script uses or displays an unintended SearXNG endpoint or additional exported values. An attacker would need the ability to influence the user's shell profil ...[truncated 519 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The README instructs users to run curl -fsSL https://get.docker.com | sh, which combines remote content retrieval with immediate shell execution. If the remote endpoint, network path, or DNS/TLS trust chain is compromised, arbitrary code would run on the user’s system with the invoking user’s privileges.

Content

Scanner excerpt · README.md (reported line 148)May include surrounding context.

brew install --cask docker

Linux (Ubuntu)

curl -fsSL https://get.docker.com | sh

text

### 端口全部占用

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose emphasizes installation/deployment, but the skill also exposes destructive behaviors such as uninstalling, deleting local directories with rm -rf, and modifying ~/.zshrc. This mismatch is dangerous because users or orchestrators may invoke the skill expecting setup only, while hidden side effects can cause data loss or persistent environment changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises shell-driven deployment behavior but does not declare any tool scope or allowed tools. In an agent environment, undeclared shell capability reduces transparency and can permit execution of system-modifying commands without clear policy gating or user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match generic requests about search, hosting, or SearXNG, increasing the chance of accidental activation. In an agent system tied to shell execution, overbroad matching can lead to unintended Docker deployment and local configuration changes on loosely related prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage description does not warn that execution will automate Docker deployment and modify OpenClaw/local environment configuration. Missing user warning undermines informed consent and makes accidental infrastructure changes more likely, especially in automated agent workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated configuration hard-codes default_lang: zh-CN, which imposes a specific language/locale choice on users. Under the policy, locale constraints should be opt-in or clearly justified as region-specific, and this script does neither.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer performs persistent user-environment modification by configuring OpenClaw through the user's shell profile, which exceeds the narrowly expected scope of deploying a SearXNG container. Even though it is not overtly malicious, persistence in ~/.zshrc creates side effects outside the service itself and can silently influence future shells and other tooling that reads the variable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script persistently alters ~/.zshrc, which is not required to start SearXNG and grants the installer a broader configuration surface than its stated role. Persistent shell startup modification is security-relevant because it survives the install session, affects future interactive environments, and could be abused as a foothold for environment-based hijacking if the pattern is normalized.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's descriptive comment and all user-facing output are in Chinese, which imposes a specific language on users. There is no indication that the skill is intended only for a Chinese-speaking environment or that users can opt into another locale.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 136)May include surrounding context.

md
- ✅ 新增幂等性检测(已安装时显示状态不重复部署)
- ✅ 新增卸载脚本 `uninstall.sh`
- ✅ 新增 `source ~/.zshrc` 生效提示
- ✅ 增强 curl 超时参数(--connect-timeout, --max-time)
- ✅ 停止旧容器逻辑(升级时清理)

## 故障排除

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 136)May include surrounding context.

md
- ✅ 新增幂等性检测(已安装时显示状态不重复部署)
- ✅ 新增卸载脚本 `uninstall.sh`
- ✅ 新增 `source ~/.zshrc` 生效提示
- ✅ 增强 curl 超时参数(--connect-timeout, --max-time)
- ✅ 停止旧容器逻辑(升级时清理)

## 故障排除

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description, triggers, and usage instructions are entirely in Chinese, which effectively forces a specific language experience without user opt-in. The file does not state that the skill is intended only for a Chinese-speaking audience or provide an alternative language option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Lines L08-L10 read from ~/.zshrc to obtain SEARXNG_BASE_URL. Although the script is a status checker, this access to user configuration data is not disclosed to the user via a comment in the action area or a user-facing message before it happens.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a one-click deployment skill for self-hosted SearXNG, while this uninstall script also edits ~/.zshrc to remove an exported environment variable. Although related to prior setup, modifying persistent shell configuration goes beyond simply removing containers and deployment files and is not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.