Back to skill

Security audit

Zzz4ai Search Engine

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese web-search helper with broad triggers, but no hidden execution, local data access, persistence, credential collection, or destructive behavior was found.

Install this only if you want informational queries routed to public Chinese search engines. Avoid private or sensitive search terms unless you are comfortable sending them to those providers, and consider narrowing triggers if your agent invokes it too often.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The changelog explicitly broadens activation to many generic everyday phrases such as '什么', '如何', '为什么', '推荐', and '最新', which greatly increases the chance the skill will trigger on unrelated conversations. Over-broad activation can cause unintended invocation, unnecessary data exposure to the skill, and tool misuse in contexts where the user did not specifically request this search capability.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list is extremely broad and includes generic terms like '什么', '如何', '为什么', '推荐', and '最新', which can cause the skill to activate for many unrelated user requests. In an agent setting, this creates routing hijack risk: ordinary conversations may be diverted into unsolicited web searches, increasing exposure of user queries to third-party sites and reducing user control over tool use.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The description frames the skill as a domestic Chinese search tool and strongly biases routing toward Chinese-language sources without explicit user opt-in. While not inherently dangerous by itself, this can override user expectations, send queries to region-specific providers, and produce censored, localized, or privacy-impacting results when the user did not ask for that behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The test prompts are extremely broad everyday phrases such as '搜索' and '找一下', which can cause the skill to trigger in many ordinary conversations where the user did not explicitly request this specific search aggregator. Over-broad activation increases the chance of unintended tool routing, privacy leakage through unnecessary external searches, and user confusion about why a China-focused search skill was invoked.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The expected outputs hard-code Chinese-local platforms like 搜狗微信、百度学术、微博、头条 without user choice, consent, or locale justification. This can steer users to region-specific providers that may have different censorship, privacy, tracking, or content-quality characteristics, and it prevents the agent from selecting a more appropriate source based on the user's preferences or jurisdiction.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.