Back to skill

Security audit

免费版Google搜索浏览器

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a Google search helper, but it asks for broad command execution without a concrete implementation or enforceable command scope.

Install only if you are comfortable giving the skill shell-command capability in the agent environment. Before use, require the publisher to provide the actual search script and a concrete allowlist or wrapper for commands, and run it in a sandboxed environment without sensitive files or credentials exposed.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill advertises that only whitelisted commands are executed, but the declared toolset includes a general-purpose exec capability with no concrete whitelist, wrapper, or enforcement mechanism documented in the file. This mismatch can cause operators or downstream agents to over-trust the skill and execute arbitrary shell commands, increasing the risk of command injection, filesystem tampering, credential exposure, or network abuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.