Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:14
Security audit
Security checks for vulnerabilities and agentic risk
This is a normal web-search helper with expected network and optional API-key configuration, and no evidence of hidden persistence, destructive behavior, or credential misuse.
Use this only for non-sensitive web research. Avoid entering secrets, private personal information, or confidential business queries, and verify the npm package/repository identity before global installation.
Detected: suspicious.env_credential_access