Google SERP Videos Search API

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Just Serp API wrapper for Google video search, with expected API-key use and network requests.

Install this only if you are comfortable sending your Google video search queries and optional localization filters to Just Serp API under your account. Keep JUST_SERP_API_KEY private and avoid entering sensitive personal, business, or investigative secrets as search terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This skill sends user-provided search queries and optional localization signals such as country, language, domain, and UULE to an external third-party API, but the manifest does not warn users about that data transfer. That can create privacy and data-handling risk, especially when users submit sensitive searches or precise location-related parameters without realizing the request leaves the host system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal