Google SERP Ai Overview API

Security checks across malware telemetry and agentic risk

Overview

The skill appears to make a disclosed, purpose-aligned external API request, with only a privacy-disclosure improvement needed.

Before installing, treat any URL you submit as data shared with Just Serp API. Avoid submitting private, internal, or sensitive URLs unless you are comfortable with that third-party processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This manifest describes a GET request to an external API and sends the required `url` query parameter to `https://api.justserpapi.com`. The file does not include any warning, disclosure, or user-facing note that the provided URL will be transmitted to a third-party service, which is a missing-warning issue for markdown/code-adjacent operation definitions under this rule.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal