Back to skill

Security audit

Web Search API

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward SearchAPI.io search helper with disclosed API-key storage and no hidden high-impact behavior found.

Install only if you are comfortable sending search queries to SearchAPI.io and storing the SearchAPI key in a plaintext config.json file in the tool directory. Review or change the default language and country settings if you do not want zh-CN/cn-localized results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The tool hard-codes `lang: 'zh-CN'` and `gl: 'cn'` as defaults, causing searches to be localized to China unless the caller explicitly overrides them. In an agent context, this can silently bias results, reduce relevance for users in other regions, and potentially route queries through a locale with different censorship, ranking, or content-availability characteristics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal