Google SERP Immersive Product API

Security checks across malware telemetry and agentic risk

Overview

This is a narrowly scoped Just Serp API helper that sends product lookup parameters to the documented API endpoint using the user's API key.

Install this only if you intend to use Just Serp API and are comfortable sending product page_token values and optional localization or seller pagination parameters to that service. Keep JUST_SERP_API_KEY in your environment or other trusted secret storage, avoid pasting it into chat or logs, and expect API usage to consume your Just Serp credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This code constructs and sends an HTTP request to an external service, including user-provided parameters in the URL query string and an API key in the request headers. There is no confirmation prompt, user-facing log/print, or comment/docstring warning that data will be transmitted off-system.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal