Back to skill

Security audit

web-search-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a simple web-search guidance skill with no executable code, persistence, credential handling, or hidden behavior observed.

Before installing, users should understand that searches and fetched URLs may be sent to external web services. Avoid using it for private, confidential, or security-sensitive information unless the surrounding agent and tools provide appropriate privacy controls.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.