Back to skill

Security audit

Google Search API

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Google search API skill that makes user-directed read-only requests to Just Serp API, with privacy considerations users should understand.

Install only if you are comfortable sending your search terms, URLs, and optional location/localization filters to Just Serp API using your API key. Avoid using it for confidential research, private URLs, or precise locations unless that disclosure is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to transmit user-supplied search queries, URLs, image URLs, and potentially precise location/localization data (for example location, uule, ll, place identifiers) to a third-party API service. Without a clear user-facing disclosure or consent mechanism, users may unknowingly send sensitive personal, business, or geographic data off-platform, creating privacy and compliance risk.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This skill exposes many operations that send user-provided queries, locations, image URLs, and other potentially sensitive inputs to a third-party SERP provider, but the documentation contains no warning about external transmission, retention, or privacy implications. In an agent setting, users may supply personal, proprietary, or sensitive research terms, and forwarding them silently to an external service creates a real data disclosure risk even if the API behavior itself is expected.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.