Back to skill

Security audit

You.com Web Search & Research CLI

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent You.com search helper that discloses its external API use and does not include executable install code or hidden persistence.

Install this only if you are comfortable sending search queries, provided URLs, and any configured You.com API key to the listed You.com services. Avoid using it for sensitive private research unless that external API exposure is acceptable, and rotate the API key if it is ever exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.