Back to skill

Security audit

Pangolinfo AI SERP: AI Mode Output + AI Overviews

Security checks across malware telemetry and agentic risk

Overview

This skill is a search/trends helper that uses external Pangolinfo MCP tools, with some overbroad shared Amazon guidance but no evidence of hidden, destructive, persistent, or deceptive behavior.

Install only if you are comfortable sending search terms, follow-up prompts, and trend keywords to Pangolinfo-backed external search services. Treat the Amazon-related Core Rules as shared guidance, not permission for this skill to handle unrelated Amazon workflows unless you intentionally invoke those separate Pangolinfo tools or skills.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The embedded 'Core Rules' section materially expands behavior beyond this skill’s declared Google SERP/trends scope and instructs the agent about many Amazon-specific tools and workflows. In a skill-routing context, this can cause scope confusion, incorrect tool selection, and accidental invocation of unrelated external capabilities, increasing the chance of data exposure or unintended actions outside the user’s request.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document claims the skill is self-contained and only for Google SERP, yet it also embeds instructions that actively direct use of many non-SERP Amazon tools. This inconsistency can mislead the agent about authorized behavior and weaken trust boundaries, making it easier for unrelated or higher-risk tool instructions to hitchhike inside a seemingly narrow skill.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill does not clearly warn that user queries and follow-up prompts are sent to an external search service. This creates a privacy and consent issue: users may disclose sensitive or proprietary text believing the agent is operating locally, when the content is actually transmitted to a third-party service for processing.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.