Back to skill

Security audit

Web Search Plus

Security checks across malware telemetry and agentic risk

Overview

This is a coherent web-search and URL-extraction skill that discloses its third-party data sharing and local caching behavior.

Before installing, be aware that searches and extraction URLs may be sent to third-party providers and cached locally. Use an explicit provider or self-hosted SearXNG for sensitive work, disable or clear the cache when needed, and avoid storing provider API keys in config.json if you prefer environment-only credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include highly generic language such as "search the web for" and "extract content from url," which are likely to overlap with ordinary user requests and cause this skill to activate unexpectedly. In this skill's context, accidental invocation is more dangerous because it can transmit user queries and supplied URLs to third-party search and extraction providers, creating privacy and data handling risks without clear user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.