Back to skill

Security audit

Web Search via SearXNG

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent SearXNG web-search skill, with expected external query transmission and optional self-hosting steps that users should review before running.

Install as a web-search integration only if you are comfortable sending search terms to the configured SearXNG instance, especially the default public instance. For self-hosting, review and pin Docker images, Python packages, and downloaded configs; understand that the Docker and systemd examples create persistent services and require explicit cleanup if you no longer want them running.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SETUP.md:15
Finding

Mutable and Unverified Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
``` 2. Pin Redis to a reviewed version and digest rather than `redis:alpine`. 3. Pin the Python package to an audited version: ```bash pip install --require-hashes -r requirements.lock ``` 4. Maintain a lock file containing exact versions and SHA-256 hashes. 5. Download the SearXNG configuration from a fixed commit rather than `master`. 6. Verify downloaded files using an independently published checksum or signature. 7. Review dependency updates before changing pinned versions. 8. Apply container hardening, including a read-only root filesystem, dropped Linux capabilities, `no-new-privileges`, resource limits, and narrowly scoped writable volumes. 9. Pin and verify all dependencies before enabling automatic restart or system-wide service persistence. ]]>

T06 · System Persistence

Note
Location
SETUP.md:238
Finding

Optional System-Wide and Container Service Persistence Exceeds Client-Only Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SETUP.md (reported line 15)May include surrounding context.

md
cd ~/searxng

# Download default config
curl -o config/settings.yml https://raw.githubusercontent.com/searxng/searxng/master/searx/settings.yml

# Run SearXNG
docker run -d \

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 91)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 182)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 183)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 238)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 239)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 240)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 241)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 297)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 300)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 301)May include surrounding context.

bash
# Install Caddy
sudo apt install caddy

# Create Caddyfile
cat > Caddyfile << 'EOF'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section installs packages, creates a system user, writes under /opt, creates a systemd unit in /etc/systemd/system, and enables and starts the service. Although these steps are expected for installation, the markdown does not explicitly warn that they make persistent host-level changes and require root privileges.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 186)May include surrounding context.

md
sudo apt install -y python3-venv python3-dev libxml2-dev libxslt1-dev

# Create user
sudo useradd -r -s /bin/false searxng

# Create directory
sudo mkdir -p /opt/searxng

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 189)May include surrounding context.

md
sudo apt install -y python3-venv python3-dev libxml2-dev libxslt1-dev

# Create user
sudo useradd -r -s /bin/false searxng

# Create directory
sudo mkdir -p /opt/searxng

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 190)May include surrounding context.

md
sudo apt install -y python3-venv python3-dev libxml2-dev libxslt1-dev

# Create user
sudo useradd -r -s /bin/false searxng

# Create directory
sudo mkdir -p /opt/searxng

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 193)May include surrounding context.

md
sudo apt install -y python3-venv python3-dev libxml2-dev libxslt1-dev

# Create user
sudo useradd -r -s /bin/false searxng

# Create directory
sudo mkdir -p /opt/searxng

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SETUP.md (reported line 239)May include surrounding context.

Enable and start:

bash
sudo systemctl daemon-reload
sudo systemctl enable searxng
sudo systemctl start searxng
sudo systemctl status searxng

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SETUP.md (reported line 261)May include surrounding context.

Check SearXNG is running:

bash
docker ps | grep searxng
curl http://localhost:8080/healthz

"No results"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill clearly performs network access to a configurable SearXNG instance, but the manifest shown in SKILL.md does not declare any tool scope such as permissions or allowed-tools. That mismatch can hide externally connected behavior from policy and review layers, increasing the risk of unintended data egress or overbroad agent use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance is extremely broad: 'search for X', 'look up Y', and similar everyday phrasing can cause the skill to trigger for many normal user requests. Because this skill sends user queries to external search infrastructure, overly broad routing increases the chance of unintentional disclosure of sensitive prompts or unnecessary network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description explains search functionality but does not warn that user queries are transmitted to a configured SearXNG instance and may then be forwarded to upstream search engines. This omission is dangerous because users or calling agents may unknowingly send confidential, regulated, or proprietary information off-platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

"Connection refused"

bash
# Check if SearXNG instance is reachable
curl https://your-searx-instance/healthz

"No results"

Static analysis

No suspicious patterns detected.