Eternal Free Search (DuckDuckGo)

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward DuckDuckGo search helper, with the main caution that search queries go to an external web service.

Install this only if you want your agent to perform DuckDuckGo searches. Avoid putting secrets, private company data, personal identifiers, or sensitive conversation context into search queries, and verify the ddgs package source/version before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and trigger scope are extremely broad ('use when you need to search the web for any information' and 'triggers on any web search need'), which can cause the agent to invoke this skill in many loosely related contexts. Over-broad routing increases the chance of unnecessary external web access, unintended data disclosure in search queries, and incorrect tool selection when a more specialized or safer skill should be used.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal