internet-search-pro网页搜索助手

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This appears to be a web-search-oriented skill with minor routing and language-scope issues, but no evidence of malicious behavior.

Install only if you are comfortable with vague research requests potentially being routed to web search. Prefer using it for explicit search requests, and consider asking the publisher to narrow triggers and state that responses should follow the user’s preferred language.

Publisher note

name: internet-search-pro description: 搜索网络获取实时信息、新闻、文档和资料 metadata: openclaw: emoji: "🔍" requires: bins: ["curl"] os: ["linux", "darwin"] clawscan: note: "Slug 'web-search' taken by /billyutw/web-search. Using 'web-search-pro' instead. Requires network for API calls to search engines." ---

SkillSpector (2)

By NVIDIA

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many ordinary requests such as '查一下' or '找资料', which can cause the skill to activate when a more appropriate tool or normal reasoning path should be used. In a tool-enabled agent, this overreach can lead to unnecessary network access, privacy leakage of user queries to external services, and reduced reliability through incorrect routing.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill description is written as Chinese-only behavior without stating that language is adaptive to the user's preference, which can cause unexpected behavior or exclusion for users interacting in other languages. While this is not a direct code-execution issue, it can misroute requests, degrade transparency, and create compliance or usability problems in multilingual deployments.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal