Back to skill

Security audit

Ddg

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward DuckDuckGo terminal-search guide, but some install paths ask users to trust unpinned third-party code with administrator privileges.

Review the installation section carefully before installing. Prefer a trusted packaged source such as the recommended snap or an official OS package, avoid the PPA or source install unless you verify the publisher and release, and treat --ducky, interactive browser opening, and --unsafe as intentional opt-in modes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Installation with Elevated Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–28
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: Medium

bash
### Via PPA:
```bash
sudo add-apt-repository ppa:twodopeshaggy/jarun
sudo apt-get update
sudo apt-get install ddgr

From source:

bash
git clone https://github.com/jarun/ddgr.git
cd ddgr
sudo make install

Technical Analysis

The installation instructions introduce third-party software through trust channels that are not pinned to a reviewed version.

Adding the PPA extends the system package manager's trust boundary to an external publisher. Packages subsequently distributed through that repository can execute installation scripts with root privileges. Although package signatures provide source authentication, they do not ensure that every future package published by the trusted source is safe.

The source installation is more directly exposed: git clone retrieves the repository's mutable default branch without selecting a specific release tag or commit and without verifying a checksum or cryptographic signature. sudo make install then invokes upstream-controlled Makefile logic as root. If the repository, publisher account, release process, or PPA is compromised, malicious installation logic could execute with full system privileges.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, PPA, signing infrastructure, or release pipeline.
  2. The attacker publishes a malicious package or modifies the default branch and its Makefile.
  3. A user follows the documented installation instructions.
  4. The system retrieves the attacker-controlled dependency through the PPA or mutable Git branch.
  5. sudo apt-get install ddgr executes package installation scripts, or sudo make install executes Makefile commands, with root privileges.
  6. The malicious dependency can modify system files, install add ...[truncated 704 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer a package from an operating-system repository or another explicitly trusted and verified publisher.
  2. Pin source installations to a reviewed immutable commit hash or signed release tag instead of cloning and executing the mutable default branch.
  3. Verify release signatures and published checksums before building or installing the software.
  4. Review the Makefile and all scripts it invokes before execution.
  5. Perform compilation as an unprivileged user in an isolated build environment.
  6. Avoid running upstream build logic with sudo. If elevated privileges are required, apply them only to the minimal final file-copy or package-installation step.
  7. Prefer building a verifiable package artifact first, inspecting its contents, and then installing that artifact through the system package manager.
  8. Document the expected publisher fingerprint, release version, immutable source reference, and verification commands so users can detect tampering.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Via Snap (recommended for Ubuntu):

bash
sudo snap install ddgr

Via PPA:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Via Snap (recommended for Ubuntu):

bash
sudo snap install ddgr

Via PPA:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

Via Snap (recommended for Ubuntu):

bash
sudo snap install ddgr

Via PPA:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
78% confidence
Finding

Adding a third-party PPA with sudo grants trust to an external package source at the system level, which increases supply-chain risk and can affect future package updates. This is more sensitive than a normal install step because it modifies the system's repository configuration with elevated privileges.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Via PPA:

bash
sudo add-apt-repository ppa:twodopeshaggy/jarun
sudo apt-get update
sudo apt-get install ddgr

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
81% confidence
Finding

The skill instructs cloning source from GitHub and then running sudo make install, which executes installation steps from fetched source code with elevated privileges. If the repository is compromised, tampered with, or replaced by an attacker-controlled fork in a copied workflow, this can lead to system-level code execution.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

bash
git clone https://github.com/jarun/ddgr.git
cd ddgr
sudo make install

Dependencies: Python 3.8 or later

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
## Troubleshooting

**Command not found:**
- Ensure ddgr is installed via snap: `sudo snap install ddgr`
- Use full command: `snap run ddgr` instead of just `ddgr`

**No results:**

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation instructs users to open search results in a browser, which changes the privacy and execution context from terminal-only to the local browser session. That can expose browsing activity to browser history, extensions, cookies, and other local session tracking, which is relevant because the skill emphasizes privacy-focused searching.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents the --unsafe flag without warning that it disables safe search and may return explicit, harmful, or otherwise unsafe content. In a general-purpose search skill, that omission can lead to accidental exposure to inappropriate results, especially in shared or automated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file includes a command labeled 'Unsafe search (disable safe search)' but does not provide any user-facing warning about potentially explicit, inappropriate, or policy-sensitive results. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user safety or privacy; disabling safe search merits at least a brief caution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.