Back to skill

Security audit

Dawn Search Suite

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed search and scraping helper with no executable install code, persistence, or hidden data handling found in the artifacts.

Before installing, understand that this skill may fetch and extract content from third-party sites, including dynamic pages. Use it only for public or authorized resources and respect applicable terms, robots policies, and privacy constraints.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly offers web search, URL extraction, and JS-rendered page scraping, but the description does not warn users about collection behavior, third-party content handling, or site-policy/legal considerations. In a scraping-focused skill, missing disclosure increases the risk of unauthorized or unexpected data extraction and unsafe use against sensitive or restricted targets.

Static analysis

No suspicious patterns detected.