Back to skill

Security audit

Web Search Plus 2.8.6

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real web search skill, but it needs Review because it stores API keys and search history locally and its SearXNG URL protection can be bypassed in ways that may reach internal network services.

Install only if you are comfortable sending searches to the configured external providers and storing provider keys plus cached query history on disk. Prefer environment variables or a properly permissioned secrets store over config.json for API keys, disable or clear caching for sensitive searches, avoid running the test script against an untrusted .env file, and use a trusted pinned SearXNG deployment rather than arbitrary instance URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.py:1939
Finding

SSRF Protection Can Be Bypassed Through Redirects or DNS Rebinding

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
test-auto-routing.sh:6
Finding

Test Script Executes the .env File as Arbitrary Shell Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.py:405
Finding

API Credentials Are Stored Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill’s declared purpose emphasizes unified search and intelligent auto-routing, but the visible content also includes local configuration, API key handling, and external instance validation behavior not clearly foregrounded in the high-level description. This mismatch can mislead users about what the skill actually does and what data or system capabilities it uses, increasing the risk of unintended exposure or overtrust.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.py (reported line 248)May include surrounding context.

python
# =============================================================================
def _load_env_file():
    """Load .env file from skill root directory if it exists."""
    env_path = Path(__file__).parent.parent / ".env"
    if env_path.exists():
        with open(env_path) as f:
            for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · FAQ.md (reported line 75)May include surrounding context.

md
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · FAQ.md (reported line 232)May include surrounding context.

md
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 75)May include surrounding context.

md
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.py (reported line 244)May include surrounding context.

python
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.py (reported line 247)May include surrounding context.

python
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.py (reported line 337)May include surrounding context.

python
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test-auto-routing.sh (reported line 6)May include surrounding context.

sh
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test-auto-routing.sh (reported line 8)May include surrounding context.

sh
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test-auto-routing.sh (reported line 13)May include surrounding context.

sh
# Test Auto-Routing Feature
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

Using source .env executes the contents of the .env file as shell code, not just as data. If an attacker can modify the repository or .env file, arbitrary commands would run when this test script is launched, which turns credential loading into code execution.

Content

Scanner excerpt · test-auto-routing.sh (reported line 7)May include surrounding context.

sh
# Tests various query types to verify routing works correctly

# Load from environment or .env file
if [ -f .env ]; then
  source .env
fi

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · CHANGELOG.md (reported line 195)May include surrounding context.

md
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · FAQ.md (reported line 239)May include surrounding context.

md
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · README.md (reported line 481)May include surrounding context.

md
#### Features
- **Privacy-Preserving**: No tracking, no profiling — your searches stay private
- **Multi-Source Aggregation**: Queries 70+ upstream engines (Google, Bing, DuckDuckGo, etc.)
- **$0 API Cost**: Self-hosted = unlimited queries with no API fees
- **Diverse Results**: Get perspectives from multiple search engines in one query
- **Customizable**: Choose which engines to use, set SafeSearch levels, language preferences

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The FAQ describes local caching of search results but does not warn that cached queries and results may contain sensitive user inputs, URLs, or derived content. On shared systems or poorly secured environments, this can create unintended data retention and local disclosure risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The FAQ explicitly recommends storing API keys in config.json without warning that plaintext credentials in configuration files are easier to leak through backups, logs, accidental commits, or local compromise. Because these keys grant access to paid external services, exposure can lead to unauthorized usage and billing abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The FAQ instructs users to run a Docker image without pinning a specific tag or digest, which can cause them to pull an unexpected or later-modified image. This creates supply-chain risk because the image content may change over time and could introduce vulnerable or malicious code into a self-hosted search instance.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · FAQ.md (reported line 139)May include surrounding context.

md
The JSON API is disabled on your instance. Enable it in `settings.yml` under `search.formats`.

### What's the API cost for SearXNG?
**$0!** SearXNG is free and open-source. You only pay for hosting (~$5/month VPS). Unlimited queries.

### When should I use SearXNG?
- **Privacy-sensitive queries**: No tracking, no profiling

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes automatic routing of user queries to multiple external providers but does not clearly warn that submitted queries may be transmitted to third parties with their own logging, retention, and privacy policies. Users may unknowingly send sensitive internal terms, personal data, or confidential research topics to outside services, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that search queries and results are automatically cached for one hour in a local .cache/ directory, but it does not warn that cached data may contain sensitive user prompts, proprietary research topics, or personal data. In a shared workstation, CI runner, or multi-user environment, this can lead to unintended retention and disclosure of searchable history and third-party response content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation describes capabilities that require environment access, file read/write, and network access, but it does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, this can cause overbroad execution privileges, making it easier for the skill to access secrets, modify local files, or send data externally without clear user visibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill markets itself as a simple search interface but does not prominently warn that user queries are transmitted to third-party providers. Queries may contain sensitive business, personal, or internal information, and silent forwarding to multiple external services can create confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation instructs users to run a Docker image without a pinned tag or digest, which can pull an unexpected or compromised latest image in the future. This creates a supply-chain risk because the actual code executed is not reproducible or integrity-locked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.