Back to skill

Security audit

bailian-search-tool-free

Security checks across malware telemetry and agentic risk

Overview

This is a web-search skill that uses an external Bailian API, with some sloppy and overbroad documentation but no artifact-backed malicious or hidden behavior.

Install only if you are comfortable sending search queries to Alibaba Bailian/DashScope using your DASHSCOPE_API_KEY. Treat the SEO/ranking language as overbroad documentation, and confirm the missing search script or runtime integration is supplied by the package source before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a Bailian web search tool, but the documentation expands its behavior into generic create/query/modify/delete/import/export modes that are unrelated to search. This kind of capability drift can mislead an agent into applying the skill in unintended contexts, increasing the chance of unsafe shell use or unauthorized data handling under the guise of a benign search utility.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The trigger conditions say the skill should be used for SEO optimization, keyword analysis, ranking improvement, and traffic optimization, which do not align with a simple web search tool. This broad and mismatched activation guidance can cause an agent to invoke the skill in inappropriate situations and potentially support search manipulation workflows beyond the declared purpose.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are overly broad and mismatched, encouraging use whenever SEO or ranking-related requests appear rather than when web search is actually needed. In an agent setting, this can cause over-invocation of an external-search-and-exec skill and route tasks into workflows that were not intended or safely bounded.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill does not warn users that their queries and possibly retrieved content will be sent to an external Bailian API service. This creates a privacy and data-governance risk because users or calling agents may submit sensitive prompts, identifiers, or proprietary material without understanding that data leaves the local environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.