Back to skill

Security audit

Bing Search (Free)

Security checks for vulnerabilities and agentic risk

Overview

This Bing/Jina search skill matches its advertised purpose, but its script can turn crafted input or returned web content into local code execution.

Review before installing or using. Do not run this skill with untrusted JSON arguments or sensitive searches, because crafted max_results values or malicious search-response content could execute local code. It should be fixed by validating max_results as an integer and passing response data to a static parser through stdin instead of embedding it in python3 -c source.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bing_search.sh:21
Finding

User-Controlled max_results Value Enables Python Code Injection

Content
View full analysis
/dev/null) ``` ### Technical Analysis The `max_results` property is extracted from attacker-supplied JSON as raw text and is not verified to be an integer. The shell comparisons attempt to enforce a range, but they do not establish that the value has a numeric JSON type or contains only decimal digits. The resulting text is subsequently interpolated directly into the source code passed to `python3 -c`: ```python matches[:$MAX_RESULTS] ``` Consequently, a crafted `max_results` string can introduce an arbitrary Python expression into the slice boundary. This is source-code injection rather than ordinary data parsing. For example, an input structurally equivalent to the following can cause Python to evaluate an attacker-controlled expression: ```json { "query": "test", "max_results": "__import__('os').system('id') or 5" } ``` After interpolation, the generated statement becomes equivalent to: ```python matches[:__import__('os').system('id') or 5] ``` The injected `os.system` call executes a local command before ...[truncated 1325 chars]
Remediation
View remediation
0) and ((.max_results // 5) | type == "number" and floor == . and . >= 1 and . <= 10) ' >/dev/null; then jq -nc '{error: "Invalid input"}' exit 1 fi MAX_RESULTS=$(echo "$JSON_INPUT" | jq -r '.max_results // 5') ``` 2. Never interpolate input values into executable Python source. Pass `MAX_RESULTS` as a positional argument and parse it as an integer inside Python: ```bash python3 parser.py "$MAX_RESULTS" ``` ```python import sys max_results = int(sys.argv[1]) if not 1 <= max_results <= 10: raise ValueError("max_results must be between 1 and 10") ``` 3. Move the parser into a fixed `.py` file rather than dynamically constructing code for `python3 -c`. 4. Return a controlled error for malformed JSON, incorrect types, and out-of-range values. Add regression tests using strings, arrays, objects, floating-point values, and Python-expression payloads as `max_results`. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bing_search.sh:38
Finding

Network Response Embedded in Python Source Enables Remote-Input Code Injection

Content
View full analysis
/dev/null) ``` ### Technical Analysis `RESPONSE` contains data obtained from an external service and ultimately derived from search-engine content. The script embeds that data directly between Python triple quotes inside a dynamically generated program: ```python response = '''$RESPONSE''' ``` Triple quotes are not a safe serialization mechanism. If the response contains a crafted `'''` sequence, it can terminate the string literal. Additional response text can then be interpreted as Python statements rather than data. A payload can use valid Python syntax and comments or a new trailing string literal to neutralize the remaining generated source. Although the connection to `r.jina.ai` uses HTTPS, transport encryption does not make the returned content trustworthy. Search results may include attacker-controlled indexed content, and compromise or malicious behavior by the upstream content-processing service could also influence the response. ### Attack Path 1. An attacker causes specially crafted text to appear in content returned for a search query, or an upstream service returns a maliciously constructed response. 2. A user or agent invokes the Skill with a query that cause ...[truncated 1068 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and documents behavior that uses network access and shell execution, but it does not declare any tool scope such as permissions or allowed-tools. This can lead to overly broad execution in host environments, making it harder for users or platforms to constrain what the skill is allowed to do and increasing the risk of unintended command or network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-provided search queries to Bing and causes page retrieval/content extraction through Jina.ai, but the description does not warn users that their queries, target URLs, and fetched content are disclosed to third-party services. This creates a privacy and data-handling risk, especially if users input sensitive terms, internal URLs, or confidential research topics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the user's raw search query to external third-party services (Jina.ai and indirectly Bing) without any disclosure, consent mechanism, or minimization. In an agent-skill context, users may enter sensitive internal terms, credentials, incident indicators, or proprietary topics, so silent exfiltration of queries to external infrastructure creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The request hardcodes setlang=zh in the Bing search URL, which imposes a specific language/locale behavior. There is no opt-in, parameterization, or documented justification showing that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions, parameter descriptions, and troubleshooting content are all presented in Chinese, while the file does not state that the skill is region-specific or offer an alternative language. This can violate a language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.