Back to skill

Security audit

联网搜索专业版

Security checks for vulnerabilities and agentic risk

Overview

This is a search/research skill with disclosed export, monitoring, API, and alert features, but users should configure its storage and alerting carefully.

Before installing, use this skill only for intended search and monitoring work, avoid putting secrets or confidential material in queries or exported reports unless you control the storage location, and review any cron/email/API settings before enabling them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The skill is presented as a search assistant but later claims generic file handling and command execution capabilities, expanding operational scope beyond the stated purpose. In an agent environment with read/exec/glob/grep tools, this kind of scope broadening can cause the agent to perform higher-risk local actions under the guise of a benign search workflow.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger conditions are broad and ambiguous, which can cause over-invocation of a skill that has exec, file, API, scheduling, and export behaviors. In practice, unclear activation criteria increase the chance that an agent will invoke this higher-privilege skill for loosely related requests, unnecessarily exposing local data or initiating networked actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises export, scheduled monitoring, and email alerts without prominently warning users about data retention, transmission, third-party exposure, or sensitive-content handling. Because the skill is meant for research and intelligence collection and can export or send alerts, insufficient disclosure raises a real privacy and security risk if users feed it confidential queries or monitored content.

Static analysis

No suspicious patterns detected.