Google SERP Search Light API

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal SERP API integration that sends search parameters to Just Serp API, with no evidence of malware or hidden destructive behavior.

Before installing, understand that searches and optional localization parameters may be sent to Just Serp API. Avoid using secrets, highly personal information, confidential business investigations, or sensitive location context in queries unless you are comfortable sharing them with that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
This skill sends user-supplied search queries and potentially sensitive localization fields such as location, country, uule, and related identifiers to a third-party service (api.justserpapi.com). While that is expected for a SERP API integration, the definition provides no user-facing disclosure, minimization, or guardrails, so users may unknowingly transmit sensitive personal, business, or investigative search terms and location context to an external processor.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal