Back to skill

Security audit

Stealthy Google Search

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised Google search task, but its installer can run newly downloaded third-party tooling with sudo/root privileges.

Install only if you are comfortable with a Google scraping helper that sends queries to Google and runs browser automation. Review the installer first, avoid running it on sensitive hosts, and do not allow the sudo step unless you have independently accepted the Scrapling dependency chain and host-level changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:21
Finding

Unpinned Third-Party Dependencies Permit Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/install.sh:27
Finding

Dynamically Installed Scrapling CLI Is Executed with Root Privileges

Content
View full analysis
/dev/null 2>&1; then echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install" sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install else echo "[stealthy-google-search] running: $SCRAPLING_BIN install" env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install fi ``` ### Technical Analysis The script executes the virtual environment's newly downloaded `scrapling` executable through `sudo` whenever the `sudo` command is present. This delegates root-level execution to third-party Python code and its dependency graph rather than limiting elevation to a small, reviewed operating-system package operation. The use of `sudo -E` additionally requests preservation of the caller's environment. Retaining environment settings while running dynamically installed Python tooling increases exposure to unsafe configuration, proxy, certificate, Python, and package-management variables. The script checks only that the file is executable; it does not authenticate the installed artifact or establish that elevated installation is required. Downloading browser assets may be necessary for the declared search function, and some system packages may require administrative installation. However, granting the entire third-party installer root privileges exceeds minimum privilege. Browser binaries can generally be installed into user-owned storage, while any required system packages should be handled separately through a reviewed and narrowly scoped administrative operation. ### Attack Path 1. An attacker introduces malicious code into the unpinned `scrapling[fetchers]` package or one of ...[truncated 1026 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill performs networked Google searches but does not declare any explicit tool scope or permissions boundaries in the skill metadata. That omission weakens least-privilege controls and transparency for operators, making it easier for a seemingly simple skill to make outbound requests without clear policy review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation states that the installer may attempt to use sudo to install Playwright system dependencies, which exceeds the expected privilege level for a search helper. Invoking privileged system-level installation expands the blast radius from a local, isolated dependency setup to host-wide modification, increasing risk if the installer or its dependency chain is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user's raw search query to Google through a live network request without any inline notice, confirmation step, or privacy warning. In this skill context, that matters because user queries may contain sensitive research topics, internal project names, credentials pasted by mistake, or other private data, and the use of a 'StealthyFetcher' makes the outbound transmission less transparent rather than more.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The install script goes beyond isolated virtualenv setup and invokes scrapling install, which can install browsers and system packages on the host. Because this action may run with elevated privileges and executes behavior from a freshly installed third-party package, it expands the trust boundary from local Python dependencies to host-level modification, creating meaningful supply-chain and privilege-risk exposure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
87% confidence
Finding

This line reflects logic that conditionally uses sudo, indicating the installer is prepared to escalate privileges during setup. Even if the echo line itself is not execution, in context it signals privileged host modification as part of installation, which is risky for an agent skill because users may run it expecting only local environment setup.

Content

Scanner excerpt · scripts/install.sh (reported line 31)May include surrounding context.

sh
# Install browsers + system deps (may require sudo).
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
  if command -v sudo >/dev/null 2>&1; then
    echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
    sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
  else

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The use of sudo -E is a stronger form of privileged execution because it preserves environment variables when invoking the root process. In an installation script for a stealth-oriented scraping tool, this increases danger: environment injection or untrusted package behavior could influence a root-level install path and lead to broader host compromise or persistence.

Content

Scanner excerpt · scripts/install.sh (reported line 32)May include surrounding context.

sh
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
  if command -v sudo >/dev/null 2>&1; then
    echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
    sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
  else
    echo "[stealthy-google-search] running: $SCRAPLING_BIN install"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The use of sudo -E is a stronger form of privileged execution because it preserves environment variables when invoking the root process. In an installation script for a stealth-oriented scraping tool, this increases danger: environment injection or untrusted package behavior could influence a root-level install path and lead to broader host compromise or persistence.

Content

Scanner excerpt · scripts/install.sh (reported line 32)May include surrounding context.

sh
SCRAPLING_BIN="$VENV/bin/scrapling"
if [ -x "$SCRAPLING_BIN" ]; then
  if command -v sudo >/dev/null 2>&1; then
    echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
    sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
  else
    echo "[stealthy-google-search] running: $SCRAPLING_BIN install"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 33)May include surrounding context.

sh
if [ -x "$SCRAPLING_BIN" ]; then
  if command -v sudo >/dev/null 2>&1; then
    echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
    sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
  else
    echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
    env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 33)May include surrounding context.

sh
if [ -x "$SCRAPLING_BIN" ]; then
  if command -v sudo >/dev/null 2>&1; then
    echo "[stealthy-google-search] running: sudo -E $SCRAPLING_BIN install"
    sudo -E env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install
  else
    echo "[stealthy-google-search] running: $SCRAPLING_BIN install"
    env DEBIAN_FRONTEND=noninteractive "$SCRAPLING_BIN" install

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command-line arguments default to English (hl=en) and US locale (gl=us), which imposes a language/region preference even when the user does not request one. This is a natural-language policy concern because the skill forces a locale choice by default rather than asking the user or remaining neutral.

Content

No source excerpt is available for this finding.