Search Engine

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only search-engine planning skill whose main consideration is disclosed local memory for preferences and project notes.

Before installing, decide whether you want this skill to remember search-engine project context across sessions or stay session-only. Avoid storing secrets, credentials, legal identifiers, or sensitive business details in ~/search-engine/ unless you explicitly choose to.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The setup instructs the skill to activate on broad concepts like 'search quality, indexing, or relevance issues' and even proactively during architecture discussions. That ambiguity can cause the skill to engage in contexts the user did not explicitly request, increasing the chance of unintended data exposure, confusion about active behavior, and unauthorized persistence of context or recommendations.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill directs storage of activation preferences in memory for future sessions and later describes maintaining internal notes, but it does not clearly notify the user at the point of collection or obtain explicit consent for persistence. In a design/architecture assistant context, those notes may include project constraints, failure patterns, and workflow preferences that can be sensitive business information even if they are not secrets.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal