Back to skill

Security audit

brave-search-tool-free

Security checks across malware telemetry and agentic risk

Overview

This is a web-search helper whose network and API-key use fit its stated purpose, with a privacy caveat for search terms and fetched pages.

Install only if you are comfortable configuring a Brave Search API key and sending search terms or target URLs to external services. Do not use it with private internal URLs, secrets, customer data, or proprietary documents unless you have approval and have checked the actual installed scripts and dependencies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill does not clearly disclose that search queries, target URLs, and fetched page contents are transmitted to external services and may be written to local files or logs. This creates a real data-handling risk because users may unknowingly send sensitive prompts, internal URLs, or proprietary content to Brave or persist them locally through redirection and archival examples.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.