梓享双擎 AI 全网搜索平台(按搜索次数收费)

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward paid web-search connector that sends search requests to a disclosed external API using a user-provided API key.

Install only if you trust the ZixiangAI search provider and are comfortable sending search terms to its API. Keep ZIXIANGAI_API_KEY secret, monitor paid usage and balance, and avoid submitting confidential personal or company data as search queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding
The skill declares a required shell script file (`scripts/search.sh`) and therefore has code-execution capability, but no explicit permissions are declared to inform or constrain that behavior. This creates a trust and review gap: operators may install a skill that can invoke shell/network actions without clear permission metadata, increasing the chance of unexpected command execution or secret handling.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends user search queries and an API key to a third-party search service, but the documentation does not provide an explicit privacy or data-sharing warning to users. As a result, users may unknowingly transmit sensitive prompts, internal data, or regulated information to an external paid provider, which is especially relevant because all queries are forwarded off-platform for processing and billing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal