Back to skill

Security audit

Searchiz AI search audit

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it runs mutable remote code and then uses its output to edit a repository, commit, and open a pull request.

Review this skill before installing. It is not evidence of malware, but it should only be used where you are comfortable running an unpinned GitHub-sourced npx tool and allowing the agent to edit files, create a branch and commit, and open a pull request. Prefer pinning the audit tool to a reviewed version and asking for confirmation before any commit or PR.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is explicitly designed to modify repository files, create a branch, commit changes, and open a pull request, but the description does not clearly warn that it will perform write actions and potentially publish changes upstream. In an agent setting, this can lead to surprising or unauthorized code changes because a user asking for an 'audit' may not realize the skill includes automated remediation and PR creation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill executes remote code directly from a GitHub repository via npx -y github:searchiz/searchiz-audit without pinning to an immutable commit or vetted package version. That creates a supply-chain risk: whoever controls the referenced repo or its dependencies can change what gets executed later, and this skill then uses that output to drive repository modifications and PR creation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.