Back to skill

Security audit

multi-search-engine

Security checks for vulnerabilities and agentic risk

Overview

This is a web-search helper skill with no hidden executable payload, but users should assume search queries and optional API keys may be exposed to third-party providers.

Install only if you are comfortable with your search terms going to the configured search providers. Do not search for secrets, tokens, private URLs, regulated data, or real passwords. If you use optional API keys, keep them out of version control and rotate them if exposed. Install dependencies in a virtual environment with pinned versions, and avoid using the remote password-generation and credential-dork examples for real workflows.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:120
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/international-search.md:183
Finding

Remote Service Recommended for Password Generation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation is written entirely in Chinese, including headings, metadata, feature descriptions, and usage guidance, without indicating that the skill is region-specific or offering an alternative language. This creates a natural-language policy concern because it imposes a specific language on users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly routes user queries to multiple third-party search engines, including privacy-sensitive and web-scraped services, but does not clearly warn users that their prompts may be transmitted externally. This can expose sensitive user input, search intent, and metadata to external providers, which is especially risky if users assume the skill is local or privacy-preserving because it advertises 'No API keys required' and privacy-focused engines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest includes multiple explicitly China-region search engines and CN-specific Bing endpoints as fixed configuration values, but the file provides no natural-language indication that users can choose or opt into that locale behavior. Under the policy rule for language/locale constraints, hard-coded locale targeting without documented choice can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to place API keys in a .env file but does not warn about secure credential handling, such as avoiding commits, limiting file permissions, and rotating exposed keys. This omission can lead to accidental disclosure of search provider credentials, enabling unauthorized API use, quota exhaustion, or billing abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document title and all instructional content are written in Chinese, and the skill does not indicate that users may choose another language or locale. Under the policy rule for natural-language constraints, forcing a specific language without opt-in is a language-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.