Back to skill

Security audit

SearXNG Local Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, disclosed guide for querying a local SearXNG search service, with some operational Docker commands users should run only intentionally.

Install this if you already use or want a local SearXNG search instance. Let the agent use the curl search examples freely, but run Docker stop/remove/recreate commands only when you intentionally want to administer that local container.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The skill’s core purpose is local web search, but it also documents operational Docker commands that can start, stop, restart, remove, and recreate a local container. In an agent setting, this expands the capability surface from read/search actions into host/container management, which could cause service disruption or unintended configuration changes if the instructions are followed automatically or exposed to an over-permissioned agent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.