T09 · Insecure Skill Coding Practices
- Location
scripts/searxng_search.py:25- Finding
Search Queries Transmitted to a Hard-Coded Endpoint over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a legitimate web-search skill, but it defaults to sending search terms to a hard-coded unencrypted SearXNG server, so users should review it before installing.
Install only if you are comfortable with your search queries being sent to the configured SearXNG instance. Prefer setting SEARXNG_ENDPOINT to a trusted HTTPS or local self-hosted instance, and avoid searching secrets, private project names, personal data, or confidential text through the default endpoint.
scripts/searxng_search.py:25Search Queries Transmitted to a Hard-Coded Endpoint over Plaintext HTTP
Forcing Chinese locale defaults and prioritizing Baidu without user opt-in can silently bias results, route traffic to region-specific providers, and mismatch user expectations about language and jurisdiction. While not a direct code-execution flaw, it can affect privacy, content integrity, and compliance by sending queries to providers the user did not choose.
The example invocations are broad, natural-language phrases that can easily overlap with ordinary user conversation, increasing the chance the skill is triggered unintentionally. Because this skill performs remote web queries, accidental activation can leak user prompts or context to an external service and cause unintended network access.
The README names a default remote SearXNG endpoint but does not warn that user queries will be transmitted to that external host. This creates a privacy and trust risk because users may unknowingly send sensitive prompts, research topics, or embedded personal data to an unvetted third-party instance over the network.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill description is broad and frames the capability as a general-purpose default for many information requests. Overly broad activation criteria can cause the agent to invoke this networked skill when not necessary, increasing data exposure to the remote search endpoint and potentially bypassing more privacy-preserving or task-appropriate alternatives.
The documentation does not clearly warn that search queries and request metadata will be transmitted to a remote SearXNG instance, whose default endpoint is a hard-coded external IP over plain HTTP. This creates privacy and integrity risk: sensitive queries may be exposed to the instance operator or intercepted in transit, and users may not understand that their inputs leave the local environment.
The instruction to 'prioritize this skill' lacks sufficient constraints and negative conditions, which can lead to over-triggering. In context, this is more concerning because the skill sends user queries to a third-party/self-hosted endpoint, so unnecessary invocation can leak prompts, topics, or sensitive search terms externally.
The tagline, description, and tags emphasize Chinese support and label the skill with a Chinese-language focus, but the manifest does not state that language selection is optional or user-configurable. Under the policy, locale or language constraints should either be optional or clearly justified as region-specific.
The code sets DEFAULT_LANGUAGE = "zh-CN", causing searches to default to a specific language/locale automatically. The file does allow override via --language, but there is no indication that this locale default is an opt-in choice or that the skill is intentionally restricted to a China-specific context.
The skill sends user search queries to a remote SearXNG instance, and the default endpoint is a hard-coded external IP over plain HTTP. This can expose potentially sensitive user queries to the remote operator and to network observers, especially because transport is not encrypted and the skill does not provide any warning or consent mechanism.
描述、命令说明和 metadata 标签中明显限定为中文语境,并包含 chinese 标签,但文档未说明这是用户可选项,或该技能为何必须限定中文/中文搜索生态。按自然语言策略,强制特定语言/地区而未提供选择或正当说明,构成轻度语言/locale 政策风险。
The manifest describes a web search skill that queries a SearXNG instance and returns structured search results. Reading environment variables such as SEARXNG_ENDPOINT and HERMES_SEARXNG_URL is not necessary to the core search function from a caller's perspective and introduces an additional capability to consume host runtime configuration.
No suspicious patterns detected.