Back to skill

Security audit

Multi Search Engine Litiao

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented search-engine helper; its main risk is that user queries are sent to external search providers, which is expected for its purpose.

Install only if you are comfortable with the agent sending search terms to the selected external search provider. Avoid using it for secrets, credentials, private URLs, personal data, or confidential project names, and use safe-search defaults unless you deliberately need otherwise.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- `references/international-search.md` - International search guide

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog documents direct use of external search engines and includes executable-style examples that send user queries to third-party services, but it does not warn that search terms may contain sensitive data and will be disclosed to external providers. In a search-integration skill, this omission can lead users or downstream agents to transmit secrets, internal URLs, or personal information without informed consent, especially across multiple providers with different privacy practices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly encourages sending arbitrary user queries to multiple third-party search engines through direct web requests, but it does not warn users that their search terms will be transmitted to external services. This can expose sensitive prompts, internal project names, credentials accidentally pasted into queries, or behavioral metadata to providers with different privacy practices, which is especially relevant because the skill advertises privacy features while also including many non-private engines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest includes multiple CN-region search providers and explicitly labels them with the "cn" region, but the file provides no natural-language indication that users can choose or opt into this locale-specific behavior. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern even in configuration values.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly documents and demonstrates DuckDuckGo's kp=-1 parameter, which disables safe search, but provides no warning about adult, graphic, or otherwise unsafe results. In a reusable agent skill, this can normalize unsafe defaults or be copied into automated workflows, increasing the chance of exposing users to harmful or policy-violating content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Startpage parameter table includes nj=0 to disable the family filter without any warning or guardrails. Because this file is an operational search guide for agents, documenting the filter-bypass parameter can directly enable unsafe searches and increase exposure to explicit or harmful material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language documentation is written in Chinese and does not indicate that this is a China-specific or Chinese-only skill, nor does it offer an alternative language or opt-in. This can conflict with language/locale policy expectations when users are not given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The documentation includes locale-specific examples such as converting USD to CNY and weather in Beijing, alongside CN-specific engines, which can signal a default regional orientation. There is no statement that the user can choose locale/region behavior or that the China-focused context is intentional and limited.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file presents all instructions and examples only in Chinese, which can amount to a language policy issue when no user opt-in or justification for the locale restriction is provided. The content includes many general-purpose search instructions, so the monolingual presentation appears to be a default rather than a clearly documented regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.