Back to skill

Security audit

DuckDuckGo Web Search

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent DuckDuckGo search skill, but its documented install command uses an unsafe system-level pip override for an unpinned third-party dependency.

Install only in a dedicated virtual environment, avoid the documented --break-system-packages command, and pin/review the ddgs dependency before use. Treat search queries as external network requests and keep sensitive private data out of queries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Unpinned Dependency Installed into the System-Managed Python Environment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/search.py:7
Finding

Documented Search Result Limit Is Not Enforced

Content
View full analysis
2 else 5 if not query: print("Usage: search.py 'query' [count]", file=sys.stderr) sys.exit(1) try: results = list(DDGS().text(query, max_results=count)) ``` The corresponding documented constraint is located at `SKILL.md`, line 19: ```markdown - `count` (optional): Number of results, default 5, max 20 ``` ### Technical Analysis Although the documentation declares a maximum result count of 20, the script passes the caller-controlled integer directly to `DDGS().text()` without range validation. It then materializes every returned result in memory using `list(...)`. An excessively large count can therefore cause unnecessary external requests, extended execution, rate limiting, or excessive memory consumption, subject to the behavior and internal limits of the `ddgs` library and DuckDuckGo. Negative values and malformed integers are also not handled consistently: malformed input raises `ValueError` before execution reaches the existing exception handler. ### Attack Path 1. An attacker or untrusted caller invokes the script with an excessive result count, such as: ```bash python3 scripts/search.py "example query" 100000000 ``` 2. The script converts the value to an integer without enforcing the documented maximum. 3. The unbounded value is passed to `DDGS().text()` as `max_results`. 4. Any results yielded by the dependency are fully accumulated through `list(...)`. 5. Depending on dependency and service behavior, the process may consume excessive time or memory, generate unnecessary network traffic, encounter upstream rate limits, or terminate unexpectedly. ### Impact Assessment The issue does not directly grant additional privileges or system access. Its primary impact is ava ...[truncated 385 chars]
Remediation
View remediation
2 else 5 except ValueError: print("Error: count must be an integer from 1 to 20.", file=sys.stderr) sys.exit(2) if not 1 <= count <= 20: print("Error: count must be from 1 to 20.", file=sys.stderr) sys.exit(2) ``` ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description includes broad activation cues such as 'look something up,' 'research a topic,' and fallback use whenever another web search tool is unavailable. This can cause the skill to trigger in many loosely related situations, increasing the chance of unnecessary web access, unintended delegation, or use on sensitive prompts where external search was not clearly requested.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language note says results are "English-biased by default," which indicates a locale/language default that may affect users without offering a language choice or opt-in. This can conflict with language or locale policy expectations when the skill is presented as generally applicable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.