Back to skill

Security audit

Integrate You.com web tools with Vercel AI SDK

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for adding You.com tools to Vercel AI SDK apps, with ordinary integration risks but no evidence of hidden or malicious behavior.

Before installing, review the npm package and lockfile, prefer a pinned version in production, keep the You.com API key in environment variables or a secrets manager, and avoid sending confidential prompts, URLs, or regulated content to the You.com tools unless that data sharing is approved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Third-Party Package Installation Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:110
Finding

API Key Literal Example Encourages Secrets in Source Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
* Using standard `YDC_API_KEY`?
   * Or custom name? (if custom, get the name)
   * Have they set it in their environment?
   * If NO: Guide them to get key from https://you.com/platform/api-keys

3. **Ask: Which AI SDK Functions?**
   * Do they use `generateText()`?

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to integrate external You.com tools that send prompts and potentially fetched/extracted web content to third-party services, but it does not prominently warn the user about that data flow. This can lead to unintended disclosure of sensitive prompts, URLs, or extracted content when developers use the integration in applications handling confidential data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.