Back to skill

Security audit

谷歌搜索专业版

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Google search automation skill with some broad wording and optional scheduling/API features that users should enable deliberately.

Install only if you want an agent to help run Google Custom Search workflows. Provide Google API credentials through environment variables, review any generated files or scheduled jobs, and require explicit approval before starting the REST API mode, creating cron schedules, sending alert emails, or writing exports outside a chosen project folder.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill for broad analytics, reporting, statistical insights, and visualization tasks, which goes well beyond a narrow Google search utility. In an agent environment, overly broad activation criteria can cause the skill to run in contexts involving file writes, command execution, and external API use when the user did not specifically request those actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition 'SEO优化、关键词分析、排名提升、搜索流量优化时使用' is ambiguous and broad enough to match many unrelated marketing or analytics requests. Because this skill also advertises exec, scheduling, API, and file-output behaviors, ambiguous activation increases the chance of unintended system-impacting actions.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill advertises file processing, API integration, command execution, and automated execution, but the warning material appears late and does not clearly foreground privacy, persistence, network egress, and system-impact risks before use. In agent workflows, users may trigger sensitive operations without realizing data may be written, transmitted externally, or scheduled for later execution.

Static analysis

No suspicious patterns detected.