Back to skill

Security audit

Web Search Instant

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed DuckDuckGo search helper with some privacy and packaging cautions, but no evidence of hidden, destructive, or deceptive behavior.

Install only if you are comfortable with your search queries being sent to DuckDuckGo. Do not use it for secrets, private internal text, or sensitive personal data, and prefer installing jq through a trusted OS package manager rather than the documented global npm command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
web-search.sh:204
Finding

Remote API Content Is Interpreted as Terminal Escape Sequences

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:169
Finding

Documentation Recommends an Unpinned Global npm Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill performs web search via the DuckDuckGo Instant Answer API. However, the supplied code chunk is not the search implementation; it is a test harness for another script. Its primary purpose is automated testing, not providing search results. Because the actual code shown executes a local tool, validates expected output, and reports pass/fail status rather than performing the declared search behavior, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for an operational web search capability using DuckDuckGo Instant Answer API. However, the supplied code does not implement web search logic or API access. It is a standalone Bash test script for another tool (web-search.sh). Its primary purpose is quality assurance: running 12 tests, checking output patterns with grep, counting related-topic lines, testing color suppression, markdown/plain formatting, quiet mode, invalid argument handling, and file output. This is a materially different primary purpose from the declared skill behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 7)May include surrounding context.

md
## API Details

- **Endpoint**: `https://api.duckduckgo.com/`
- **Parameters**:
  - `q` - Search query (URL-encoded)
  - `format=json` - JSON response

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

Some abstracts have Unicode issues in basic parsing (non-ASCII characters garbled). Install jq for cleaner output:

bash
sudo apt-get install jq  # Ubuntu/Debian
brew install jq          # macOS

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

Some abstracts have Unicode issues in basic parsing (non-ASCII characters garbled). Install jq for cleaner output:

bash
sudo apt-get install jq  # Ubuntu/Debian
brew install jq          # macOS

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation describes shell execution and network access but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, that weakens policy enforcement and can let the skill be invoked with broader capabilities than users or reviewers expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger guidance is very broad, including generic phrases like 'what is', 'how to', and 'find information'. In agent orchestration, this can cause unintended invocation, unnecessary network access, and routing of prompts containing sensitive data into an external search tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends the user's raw search query to DuckDuckGo over the network without any explicit privacy notice, consent step, or warning at execution time. In an agent-skill context, queries may contain sensitive user data or internal prompts, so silent transmission to a third-party service creates a real privacy and data-exposure risk even though the behavior is expected for a web-search tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.