anysearch
Fail
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The
.envfile contains a hardcoded API key (ANYSEARCH_API_KEY=as_sk_16c4f23c66e3a3b9c9683f79090fa912). - [DATA_EXFILTRATION]: The
batch_searchcommand in all four CLI scripts (anysearch_cli.py,anysearch_cli.js,anysearch_cli.ps1,anysearch_cli.sh) supports reading from local files using the@prefix (e.g.,--queries @/path/to/file). The contents of these files are subsequently sent to the external API athttps://api.anysearch.com/mcp, creating a potential path for sensitive data exfiltration. - [COMMAND_EXECUTION]: The
README.mdandSKILL.mdprovide detailed instructions for the agent to execute shell commands for platform detection, runtime verification, and file system operations (writingruntime.conf). - [EXTERNAL_DOWNLOADS]: The documentation instructs the agent and user to download the skill package from an external repository (
github.com/anysearch-ai/anysearch-skill) usingcurlorwget.
Recommendations
- AI detected serious security threats
Audit Metadata