Back to skill

Security audit

Everything Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local Windows file-search helper, but users should understand it can reveal local filenames and paths through Everything's HTTP server.

Install only if you want an agent or scripts to query your Everything index. Keep the Everything HTTP server bound to 127.0.0.1 when possible, enable authentication before any remote access, and avoid running broad or person-name searches on shared or sensitive systems unless you are comfortable exposing matching filenames and full paths in output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises search functionality but the content includes local process enumeration, port probing, local HTTP requests, and references to reading configuration paths. Even if intended for setup/troubleshooting, this broadens the effective capability of the skill and can expose system details or normalize reconnaissance under an unrelated description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises search functionality but the content includes local process enumeration, port probing, local HTTP requests, and references to reading configuration paths. Even if intended for setup/troubleshooting, this broadens the effective capability of the skill and can expose system details or normalize reconnaissance under an unrelated description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill demonstrates network access, localhost probing, and shell/diagnostic commands, but it does not declare any tool scope or permissions boundary. In an agent environment, undocumented capabilities increase the chance of overbroad execution and make it harder for users or policy controls to assess what the skill may access or run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to enable Everything's HTTP server but does not warn that it exposes searchable file metadata and results over a local web interface. If the server is misconfigured, bound beyond localhost, or accessed by another local process, sensitive filenames and paths may be disclosed.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

bash
# 测试 HTTP 服务器是否运行
python -c "import urllib.request; r = urllib.request.urlopen('http://127.0.0.1:2853/', timeout=5); print('OK:', r.status)"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The API documentation explicitly promotes searching local files, documents, and photos of named individuals, but it provides no warning about handling sensitive personal or confidential data. In an agent skill context, this omission can normalize broad filesystem discovery and make it easier for downstream agents or users to use the capability for privacy-invasive enumeration without appropriate consent, scoping, or safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This example explicitly searches for photos of a named person and then prints full filesystem paths for matching files. In a multi-user environment, shared terminal, logs, screenshots, or copied output, this can expose sensitive personal data and file locations without any warning, consent check, or output minimization.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/check-config.py (reported line 25)May include surrounding context.

python
try:
        import subprocess
        result = subprocess.run(
            ["tasklist", "/FI", "IMAGENAME eq Everything.exe"],
            capture_output=True,
            text=True,

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/check-config.py (reported line 69)May include surrounding context.

python
print("[3/4] Checking HTTP server...")
    
    try:
        req = urllib.request.Request('http://127.0.0.1:2853/')
        req.add_header('User-Agent', 'Mozilla/5.0')
        
        with urllib.request.urlopen(req, timeout=5) as response:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose.py (reported line 34)May include surrounding context.

python
try:
        import subprocess

        result = subprocess.run(
            ["tasklist", "/FI", "IMAGENAME eq Everything.exe"],
            capture_output=True,
            text=True,

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/diagnose.py (reported line 84)May include surrounding context.

python
print("\n[3/6] Checking HTTP Server...")

    try:
        req = urllib.request.Request("http://127.0.0.1:2853/")
        req.add_header("User-Agent", "Mozilla/5.0")

        start = time.time()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends the user's search keyword and derived filters over HTTP to an Everything HTTP Server endpoint, which can expose sensitive local search intent and file-system context. Although the module docstring mentions the API, there is no confirmation prompt, visible log, or explicit warning near execution that user queries are being transmitted to a server process.

Content

No source excerpt is available for this finding.

Dynamic Request Target

Medium
Category
Server-Side Request Forgery
Confidence
74% confidence
Finding

The code builds an HTTP request target from dynamic host and port inputs and performs a network request without any allowlist or validation. If untrusted input can reach this helper, it could be used to probe internal services or trigger requests to unintended local or remote endpoints, which is a classic SSRF-style primitive even though the default target is localhost.

Content

Scanner excerpt · src/utils.py (reported line 72)May include surrounding context.

python
if result == 0:
            # Try HTTP request
            import urllib.request
            req = urllib.request.Request(f"http://{host}:{port}/")
            with urllib.request.urlopen(req, timeout=timeout) as response:
                return response.status == 200
        return False

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill's title and documentation are written in Chinese and explicitly emphasize Chinese/English search support, but the user-facing documentation does not offer a language or locale choice. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document repeatedly uses Chinese keywords such as "关键词", "数据资产", "报告", and "文档" in examples and specifically instructs users to encode Chinese keywords. This creates a natural-language locale preference in the skill documentation without an explicit user opt-in or a documented justification that the skill is intended only for Chinese-language usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This Python code performs a filesystem search and prints matching file names, full paths, and sizes to stdout, which can expose sensitive local information. While the script prints what query is being run, the module docstring only describes usage and does not warn users that search results may reveal private file locations and metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The only usage example shown to users uses the Chinese term "数据资产", which implicitly biases the skill toward a specific language without stating that other languages are equally supported. Under the language/locale policy, examples should avoid forcing or implying a specific language unless the locale-specific scope is explicit and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code prints each result's full local path directly to the console, which can reveal sensitive directory names or file locations. Although the script logs that a search is occurring, it does not disclose that detailed filesystem metadata will be displayed to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring's usage example specifies only Chinese search terms, which can be read as prescribing a specific language for use. The file does not offer language choice or explain why Chinese-only examples are required, so this may violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a Windows file search skill using an HTTP API with fuzzy matching and file-type filtering. This diagnostic helper invokes tasklist via subprocess.run to enumerate local processes, which is an operational troubleshooting capability rather than a direct file-search function and is not justified by the stated search purpose alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language examples explicitly use Chinese search terms such as "数据资产" and "张三", which suggests a language-specific usage pattern. Because the file does not state that this is merely an example or offer any language/locale choice, it may be interpreted as a locale preference without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The search_photos docstring uses a Chinese-only example name, which can imply a language or locale expectation in natural-language guidance. There is no accompanying statement that names and queries in other languages are equally supported, so the example may create an unnecessary locale bias.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language docstring explicitly frames the function around handling Chinese characters and keywords that can contain Chinese. This introduces a language-specific assumption in the skill text without offering user choice or documenting why a Chinese-specific constraint is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.