Back to skill

Security audit

Performs web searches using DuckDuckGo to retrieve real-time information from the internet. Use when the user needs to search for current events, documentation, tutorials, or any information that requires web search capabilities.

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate DuckDuckGo search skill, but it asks for broad local command and package-install authority that is wider than simple search requires.

Review this skill before installing. Use it in a dedicated virtual environment, pin and verify dependency versions, avoid entering secrets or internal queries, and treat search results as untrusted. Be especially cautious about granting an agent broad Python, pip, or uv command access when a narrower search wrapper would be enough.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Third-Party Package Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–27 and 401–407
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

The skill instructs users or agents to install the latest available release of duckduckgo-search and, in one example, to upgrade pip without pinning versions or verifying package integrity.

bash
# Use uv to install (recommended)
uv pip install duckduckgo-search

# Or use pip
pip install duckduckgo-search

The installation troubleshooting section repeats the unsafe installation pattern:

bash
# Ensure pip is the latest version
pip install --upgrade pip
pip install duckduckgo-search

# Or use uv
uv pip install duckduckgo-search

Technical Analysis

These commands resolve mutable package versions from the configured Python package index. No exact version, package hash, lock file, trusted index URL, or dependency integrity control is specified. Consequently, the code installed by the command can change after the skill has been reviewed.

Python packages and their transitive dependencies can execute code during installation or when imported by the documented search examples. If a future package release, transitive dependency, configured package index, or package maintainer account is compromised, following these instructions could introduce attacker-controlled code.

The unconditional pip install --upgrade pip instruction unnecessarily modifies a foundational environment tool and broadens the supply-chain changes made while setting up this skill.

Attack Path

  1. An attacker compromises a future duckduckgo-search release, one of its transitive dependencies, a package-maintainer account, or the package index configured in the target environment.
  2. A user or agent follows the installation instructions in SKILL.md.
  3. pip or uv resolves and downloads the mutable latest package release without checking an expecte ...[truncated 1047 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin duckduckgo-search to a specific version that has been reviewed and tested:
    bash
    python -m pip install "duckduckgo-search==<reviewed-version>"
    
  2. Record all direct and transitive dependencies in a lock file and require cryptographic hashes, for example through a hash-locked requirements file:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Document the expected trusted package index and prevent fallback to untrusted or unintended indexes.
  4. Install the dependency inside a dedicated virtual environment with only the permissions required for web searching.
  5. Remove the blanket pip install --upgrade pip instruction. If a minimum pip version is genuinely required, document and pin the reviewed version separately.
  6. Establish a dependency-update process that includes package-origin verification, changelog review, vulnerability scanning, and regeneration of approved hashes before changing pinned versions.
  7. Treat content returned by web searches as untrusted data and do not automatically execute commands or follow instructions embedded in result text or opened pages.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends user queries and associated metadata to external services (DuckDuckGo and potentially proxies) but does not clearly disclose this data flow. In agent environments, users may provide sensitive or internal information; absent disclosure increases the risk of unintended data leakage to third parties and intermediary proxy operators.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares Bash access for arbitrary Python execution plus package installation via pip and uv, which exceeds the stated purpose of performing web searches. This expands the attack surface significantly: a prompt injection or misuse of the skill could install untrusted packages or execute arbitrary code under the guise of a search operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description switches to Chinese at L009 and continues primarily in Chinese for instructions and examples. This imposes a specific language on users without opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented example saves search results to a local JSON file, which is outside the skill's stated search-only purpose and introduces unnecessary write capability. While not inherently malicious, file output can persist sensitive queries or retrieved data locally and may be abused for staging or exfiltration workflows in a broader attack chain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.