Back to skill

Security audit

SerpApi

Security checks across malware telemetry and agentic risk

Overview

This is a coherent SerpApi search skill with disclosed one-time setup steps that users should review before running.

Install only if you want to use SerpApi through OOMOL. Let the skill run read-only search actions, but review and approve any first-time CLI install, login, connection, or billing step yourself before it is performed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest presents the skill as a read/search interface, but the documented fallback flow permits side-effecting operations such as installing software and initiating authentication. This mismatch can cause an agent or user to invoke the skill under a low-risk assumption while it may execute commands that alter the environment or account state.

Intent-Code Divergence

Low
Confidence
80% confidence
Finding
The safety section says untagged actions are safe reads, but the same document includes first-time setup commands with significant side effects, including software installation and authentication. This can weaken operator caution and encourage execution of privileged setup steps under a misleading safety model.

VirusTotal

44/44 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.