Back to skill

Security audit

Brave Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Brave Search integration through Maton; its extra documented search endpoints broaden the description slightly but do not show hidden or unsafe behavior.

Before installing, expect to authenticate with Maton and authorize a Brave Search connection. Review that the skill can call documented Brave Search passthrough endpoints, including local POI, autosuggest, spellcheck, and summaries, and prefer OAuth over long-lived API keys.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest and top-level description scope the skill to web, image, news, and video search, but the documented passthrough also exposes local POI lookup, autosuggest, spellcheck, and summarizer APIs. This mismatch can cause downstream policy engines or users to authorize a broader capability set than they understand, weakening least-privilege assumptions and enabling unintended data access or actions through undocumented endpoints.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The file states that access is scoped to web search, news search, image search, and summaries, but elsewhere documents local POI, autosuggest, and spellcheck endpoints. Contradictory scope documentation undermines informed consent and can lead an agent or user to operate under false assumptions about what the connection can access.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.