Security audit
web-search-skill
Security checks for vulnerabilities and agentic risk
Overview
This is a simple web-search guidance skill with no executable code, persistence, credential handling, or hidden behavior observed.
Before installing, users should understand that searches and fetched URLs may be sent to external web services. Avoid using it for private, confidential, or security-sensitive information unless the surrounding agent and tools provide appropriate privacy controls.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
