Multi Search Engine.Tmp

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only search helper whose main risk is that user queries are sent to external search engines.

Install only if you want an agent to use documented external search-engine URLs. Do not include passwords, tokens, personal identifiers, or confidential business information in search queries, and use advanced operators only for authorized research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly encourages sending user-supplied search terms to multiple third-party search providers, but it does not warn that those queries may contain sensitive data and will be disclosed to external services. In an agent context, users may assume searches are local or privacy-preserving, so the omission can lead to inadvertent leakage of personal, proprietary, or confidential information to search engines with varying tracking and logging practices.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal