Back to skill

Security audit

SearXNG Self-Hosted Search

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent SearXNG search helper, but its setup instructions can expose an unauthenticated persistent search service and rely on mutable container code without enough warning.

Install only if you are comfortable operating a SearXNG service. Bind it to localhost or a private network, replace the placeholder secret with a random value, avoid putting secrets or sensitive project names in searches, and pin the container image to a reviewed version or digest before long-term use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Public Service Exposure with a Predictable Application Secret

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–30 and 42–43
Vulnerability Type: Insecure network configuration and hardcoded placeholder secret
Risk Level: Medium

Vulnerable Code:

yaml
ports:
  - "8080:8080"
yaml
server:
  secret_key: "change-me-to-random-string"
  bind_address: "0.0.0.0"

Technical Analysis

Docker publishes the mapping 8080:8080 on all host interfaces by default. The accompanying SearXNG configuration explicitly binds the application to 0.0.0.0, making it reachable from external networks wherever host and network firewall rules permit access.

The setup also writes a predictable placeholder value into server.secret_key. Although the value indicates that it should be changed, the provided executable setup neither generates a secure random secret nor prevents deployment with the placeholder. Any security control that relies on this secret may consequently operate with a publicly known value.

The documented endpoint uses unencrypted HTTP and does not configure authentication or a TLS reverse proxy. External deployment using the instructions as written can therefore expose search queries and the service itself to unauthorized parties.

Attack Path

  1. A user copies the documented Docker Compose and SearXNG configuration.
  2. SearXNG listens on every container network interface because bind_address is 0.0.0.0.
  3. Docker publishes container port 8080 on every host interface.
  4. A remote attacker scans for or otherwise discovers the exposed port.
  5. The attacker directly accesses the unauthenticated search endpoint and submits arbitrary requests.
  6. The attacker can consume system resources and upstream search capacity. Network intermediaries may also observe plaintext HTTP queries.
  7. If application functionality relies on server.secret_key, the known placeholder further weakens the corresponding secret-dependent protections.

I

...[truncated 577 chars]

Remediation
View remediation

Remediation Suggestions

  • Bind the published Docker port to loopback by default:

    yaml
    ports:
      - "127.0.0.1:8080:8080"
    
  • Generate a cryptographically secure secret rather than storing a placeholder. For example, generate it with openssl rand -hex 32 and inject it through a protected configuration file or secret-management mechanism.

  • Make deployment fail when the placeholder secret remains configured.

  • For remote access, place SearXNG behind an authenticated TLS reverse proxy and restrict access through firewall rules, a VPN, or an explicit IP allowlist.

  • Do not expose the service directly to the public internet.

  • Document that the default HTTP endpoint is suitable only for loopback or another trusted private network.

  • Apply request throttling and resource limits to reduce abuse and denial-of-service risk.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Mutable Latest Container Image Permits Unreviewed Dependency Changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 27
Vulnerability Type: Mutable third-party container dependency
Risk Level: Medium

Vulnerable Code:

yaml
image: searxng/searxng:latest

Technical Analysis

The latest tag is mutable and does not identify a fixed, reproducible container artifact. A deployment performed later may execute different image contents even though the project configuration has not changed. This prevents the reviewed dependency from being reliably associated with the artifact eventually executed by users.

The image name is consistent with the software described by the Skill, and the audited material contains no evidence that the current upstream image is malicious. The risk arises from relying on a mutable external artifact: an upstream account or registry compromise, unauthorized tag replacement, or unexpected breaking update could cause future installations to execute unreviewed code.

Attack Path

  1. A user follows the setup instructions and runs docker compose up -d.
  2. Docker resolves searxng/searxng:latest from the external registry.
  3. The registry tag changes because of a routine release, unauthorized replacement, or upstream compromise.
  4. A new installation or image pull retrieves the changed artifact without any modification to SKILL.md.
  5. Docker executes the unreviewed image with the network access, published port, restart policy, and writable configuration volume declared in the Compose file.
  6. If the substituted image is malicious, it can manipulate mounted configuration data, send network traffic, expose additional application behavior, or consume container and host resources available through the Docker configuration.

Impact Assessment

A compromised or unexpectedly changed image can execute arbitrary code inside the container. Its direct access includes the writable ./searxng:/etc/searxng volume, container network connectivity, ...[truncated 354 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the image to a reviewed, explicit release version instead of latest.

  • For reproducible and tamper-resistant deployment, also pin the immutable image digest:

    yaml
    image: searxng/searxng@sha256:REVIEWED_IMAGE_DIGEST
    
  • Verify the digest against an authenticated official release source before documenting it.

  • Perform image updates through an explicit review process that includes vulnerability scanning, release-note review, and testing.

  • Configure automated monitoring for vulnerabilities affecting the pinned image, while keeping deployment updates subject to approval.

  • Consider signature or provenance verification where supported by the image publisher and deployment environment.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages sending arbitrary search queries to a configured SearXNG server and, by design, onward to upstream search engines, but it does not warn users that query contents leave the local agent context. This can lead to unintended disclosure of sensitive prompts, internal project names, credentials, or personal data if users treat the search as purely local or private.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language configuration example specifies default_lang: "en", which imposes a language default in the skill documentation. The file does not present this as optional user choice or explain a region-specific need, so it can be read as forcing a locale preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.