super-search-engine

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for running searches across public search engines, with expected external query sharing and no hidden execution or persistence.

Safe to install as a search helper, but avoid putting secrets, credentials, internal hostnames, private incident details, personal data, or regulated information into search queries unless you are comfortable sharing them with the selected search provider. Use advanced search operators only for legitimate, authorized research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill encourages users to issue queries directly to multiple third-party search engines but does not disclose that those queries will be transmitted over the network to external services. This can expose sensitive prompts, internal hostnames, investigation topics, or personal data to search providers, and the lack of warning increases the chance of accidental data leakage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal