Back to skill

Security audit

WebSearch with SerpApi

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward SerpAPI search skill with some credential and dependency hygiene issues, but no evidence of hidden or unrelated behavior.

Install only in an environment where you are comfortable giving the skill access to a SerpAPI key and sending your search queries to SerpAPI. Prefer setting SERPAPI_API_KEY through a secret manager or environment variable, do not hardcode it into the Python file, and consider pinning or locking the serpapi dependency before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:29
Finding

Setup Documentation Encourages API-Key Hardcoding

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · serpapi_search.py (reported line 6)May include surrounding context.

python
from typing import Optional

def serpapi_search(query: str, engine: str = "google") -> Optional[str]:
    # Get API key from environment variable or use default
    api_key = os.getenv("SERPAPI_API_KEY", "")
    if not api_key:
        return "Error: SerpAPI key not found. Set SERPAPI_API_KEY environment variable."

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill metadata declares Python execution and the documentation explicitly references use of the SERPAPI_API_KEY environment variable, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an authorization/visibility gap where the skill's access to sensitive environment data is not explicitly constrained or disclosed, increasing the risk of secret exposure or overly broad runtime privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.