T09 · Insecure Skill Coding Practices
- Location
web-search.sh:204- Finding
Remote API Content Is Interpreted as Terminal Escape Sequences
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed DuckDuckGo search helper with some privacy and packaging cautions, but no evidence of hidden, destructive, or deceptive behavior.
Install only if you are comfortable with your search queries being sent to DuckDuckGo. Do not use it for secrets, private internal text, or sensitive personal data, and prefer installing jq through a trusted OS package manager rather than the documented global npm command.
web-search.sh:204Remote API Content Is Interpreted as Terminal Escape Sequences
SKILL.md:169Documentation Recommends an Unpinned Global npm Dependency
The declared description says this skill performs web search via the DuckDuckGo Instant Answer API. However, the supplied code chunk is not the search implementation; it is a test harness for another script. Its primary purpose is automated testing, not providing search results. Because the actual code shown executes a local tool, validates expected output, and reports pass/fail status rather than performing the declared search behavior, the description does not accurately represent this code chunk.
The declared description is for an operational web search capability using DuckDuckGo Instant Answer API. However, the supplied code does not implement web search logic or API access. It is a standalone Bash test script for another tool (web-search.sh). Its primary purpose is quality assurance: running 12 tests, checking output patterns with grep, counting related-topic lines, testing color suppression, markdown/plain formatting, quiet mode, invalid argument handling, and file output. This is a materially different primary purpose from the declared skill behavior, so it should be flagged as a mismatch.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## API Details
- **Endpoint**: `https://api.duckduckgo.com/`
- **Parameters**:
- `q` - Search query (URL-encoded)
- `format=json` - JSON response
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Some abstracts have Unicode issues in basic parsing (non-ASCII characters garbled).
Install jq for cleaner output:
sudo apt-get install jq # Ubuntu/Debian
brew install jq # macOS
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Some abstracts have Unicode issues in basic parsing (non-ASCII characters garbled).
Install jq for cleaner output:
sudo apt-get install jq # Ubuntu/Debian
brew install jq # macOS
The skill documentation describes shell execution and network access but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, that weakens policy enforcement and can let the skill be invoked with broader capabilities than users or reviewers expect.
The trigger guidance is very broad, including generic phrases like 'what is', 'how to', and 'find information'. In agent orchestration, this can cause unintended invocation, unnecessary network access, and routing of prompts containing sensitive data into an external search tool.
The script sends the user's raw search query to DuckDuckGo over the network without any explicit privacy notice, consent step, or warning at execution time. In an agent-skill context, queries may contain sensitive user data or internal prompts, so silent transmission to a third-party service creates a real privacy and data-exposure risk even though the behavior is expected for a web-search tool.
No suspicious patterns detected.