N2 Free Search

Security checks across malware telemetry and agentic risk

Overview

This is a coherent web-search skill, with ordinary npm-package trust and public-search privacy risks users should understand before use.

Install only if you trust the `n2-free-search` npm package and publisher. For sensitive research, use the self-hosted `SEARXNG_URL` mode; avoid putting passwords, tokens, personal data, internal URLs, or confidential business details into public-mode searches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The public-mode configuration directs agent search traffic to an external SearXNG service but the documentation does not clearly warn users that their prompts, queries, and possibly sensitive research terms will leave the local environment. In an agent setting, this can cause unintentional disclosure of confidential data because users may assume a local or privacy-preserving default from phrases like 'private' and 'zero setup.'

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal