Back to skill

Security audit

SearXNG Web Search

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate web-search skill, but it defaults to sending search terms to a hard-coded unencrypted SearXNG server, so users should review it before installing.

Install only if you are comfortable with your search queries being sent to the configured SearXNG instance. Prefer setting SEARXNG_ENDPOINT to a trusted HTTPS or local self-hosted instance, and avoid searching secrets, private project names, personal data, or confidential text through the default endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/searxng_search.py:25
Finding

Search Queries Transmitted to a Hard-Coded Endpoint over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Forcing Chinese locale defaults and prioritizing Baidu without user opt-in can silently bias results, route traffic to region-specific providers, and mismatch user expectations about language and jurisdiction. While not a direct code-execution flaw, it can affect privacy, content integrity, and compliance by sending queries to providers the user did not choose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example invocations are broad, natural-language phrases that can easily overlap with ordinary user conversation, increasing the chance the skill is triggered unintentionally. Because this skill performs remote web queries, accidental activation can leak user prompts or context to an external service and cause unintended network access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README names a default remote SearXNG endpoint but does not warn that user queries will be transmitted to that external host. This creates a privacy and trust risk because users may unknowingly send sensitive prompts, research topics, or embedded personal data to an unvetted third-party instance over the network.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description is broad and frames the capability as a general-purpose default for many information requests. Overly broad activation criteria can cause the agent to invoke this networked skill when not necessary, increasing data exposure to the remote search endpoint and potentially bypassing more privacy-preserving or task-appropriate alternatives.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation does not clearly warn that search queries and request metadata will be transmitted to a remote SearXNG instance, whose default endpoint is a hard-coded external IP over plain HTTP. This creates privacy and integrity risk: sensitive queries may be exposed to the instance operator or intercepted in transit, and users may not understand that their inputs leave the local environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to 'prioritize this skill' lacks sufficient constraints and negative conditions, which can lead to over-triggering. In context, this is more concerning because the skill sends user queries to a third-party/self-hosted endpoint, so unnecessary invocation can leak prompts, topics, or sensitive search terms externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tagline, description, and tags emphasize Chinese support and label the skill with a Chinese-language focus, but the manifest does not state that language selection is optional or user-configurable. Under the policy, locale or language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code sets DEFAULT_LANGUAGE = "zh-CN", causing searches to default to a specific language/locale automatically. The file does allow override via --language, but there is no indication that this locale default is an opt-in choice or that the skill is intentionally restricted to a China-specific context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user search queries to a remote SearXNG instance, and the default endpoint is a hard-coded external IP over plain HTTP. This can expose potentially sensitive user queries to the remote operator and to network observers, especially because transport is not encrypted and the skill does not provide any warning or consent mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

描述、命令说明和 metadata 标签中明显限定为中文语境,并包含 chinese 标签,但文档未说明这是用户可选项,或该技能为何必须限定中文/中文搜索生态。按自然语言策略,强制特定语言/地区而未提供选择或正当说明,构成轻度语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes a web search skill that queries a SearXNG instance and returns structured search results. Reading environment variables such as SEARXNG_ENDPOINT and HERMES_SEARXNG_URL is not necessary to the core search function from a caller's perspective and introduces an additional capability to consume host runtime configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.