Back to skill

Security audit

koopje-search

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward koopje.ai search integration with disclosed API use, an API key requirement, and no bundled executable code or persistence.

Install this only if you are comfortable sending your koopje.ai searches, listing URLs, and any optional postcode or coordinates you provide to koopje.ai. Keep the KOOPJE_API_KEY private, and use less precise location filters unless exact distance matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger guidance is broad enough to match ordinary shopping and pricing requests, which can cause the assistant to invoke this skill in situations where the user did not clearly ask to use koopje.ai. That creates an overbroad activation boundary and may lead to unnecessary third-party data sharing or tool use, even though the skill itself is only a search API and not directly destructive.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
Defaulting responses to Dutch without user opt-in can override the user's language preference and cause confusing or inaccessible output. This is primarily a policy and UX boundary issue rather than a classic security flaw, but it can still lead to unintended behavior when the assistant follows skill instructions over the user's apparent language context.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This markdown file describes sending `lat`/`lng` and postcode-derived location data to the API, which can affect user privacy. The reference explains the parameters and response fields but does not warn users that precise location data will be transmitted to the service.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The markdown instructs users to send an API key in the `Authorization` header and later describes key creation and storage, but it does not warn against exposing keys in client-side code, logs, or shared environments. Because credentials affect account security, a minimal handling warning is appropriate in the skill description.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The `/v1/answer` description states 'RAG answer (Dutch)' as a fixed behavior. This is a natural-language locale restriction presented without user choice or an explicit justification that the endpoint is intentionally region- or language-specific.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.