Back to skill
Skillv1.0.0

VirusTotal security

Searxng Backup · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewApr 30, 2026, 6:12 AM
Hash
e052b952f6115ffffaadf8d418277bc9fe16dd665c3fa946b6b1fc62ed80cbf0
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: searxng-backup Version: 1.0.0 The skill provides a search interface for SearXNG but contains a security vulnerability in `scripts/searxng.py` where SSL certificate verification is explicitly disabled (`verify=False`) and associated warnings are suppressed. While the documentation states this is for local self-signed certificates, this flaw allows for potential Man-in-the-Middle (MITM) attacks if the agent is configured to use a remote or public SearXNG instance via the `SEARXNG_URL` environment variable.
External report
View on VirusTotal