Zenserp

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal Zenserp search helper, but users should know their search terms are sent to a third-party service.

Before installing, treat this as an external search integration: do not include secrets, private customer data, unreleased project names, or sensitive internal research terms in searches unless you are comfortable sending them to Zenserp.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill instructs users to send search payloads to Zenserp but does not warn that the query contents and related parameters will be transmitted to an external third-party service. This creates a real data disclosure risk because users may include sensitive terms, identifiers, or internal research queries without understanding the external exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal