Back to skill

Security audit

Google SERP Videos Search API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow Just Serp API wrapper for Google video search and its network/API-key use is disclosed and purpose-aligned.

Install only if you intend to use Just Serp API for Google video search. Keep JUST_SERP_API_KEY in your environment and remember that search queries and optional filters are sent to Just Serp API.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a network-capable helper (node .../bin/run.mjs) that performs external API requests, but the manifest does not explicitly declare tool scope such as permissions or allowed-tools. This creates a governance and sandboxing gap: an agent platform may permit broader-than-intended execution or fail to enforce least privilege, making unintended outbound requests easier if the skill is repurposed or chained with untrusted input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.