Google Search Grounding 3

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Google search helper that sends search queries to Google APIs and shows no hidden, destructive, or persistent behavior.

Install only if you are comfortable sending search queries to Google/Gemini using your Google API key. Use a restricted key with quotas, avoid searching for secrets or sensitive internal data, set language and country defaults if Hebrew/Israel results are not desired, and consider installing the Python dependency in a virtual environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill is explicitly a web search tool that sends user queries to external Google services, but the description does not warn users that their prompts, queries, and possibly related context may leave the local environment. This creates a real privacy and compliance risk, especially if users pass sensitive internal data, PII, or confidential research terms.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Defaulting searches to Hebrew (`he`) and Israel (`IL`) without explicit opt-in can silently alter routing, localization, and result profiling in ways users may not expect. This can expose user regional assumptions, bias results toward a specific locale, and create privacy or policy issues for users in other jurisdictions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal