Back to skill

Security audit

搜索

Security checks across malware telemetry and agentic risk

Overview

This search-helper skill is not malicious, but it asks for command and file-access capabilities that are broader than its stated internet-search purpose.

Review this skill before installing. It appears to be a generic search helper and contains no malicious payload, but only install it if you are comfortable granting the agent command execution and local file-access tools for a skill whose documented purpose is mostly internet search guidance. Prefer a version that removes exec and narrows file access unless you specifically need those capabilities.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill’s manifest and top-level description present it as a narrow guide for using internet_search, but later sections expand its scope to file handling, API integration, and command execution. This mismatch can cause an agent or reviewer to grant broader trust and permissions than users would reasonably expect, increasing the risk of unintended tool use and capability abuse.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising command execution in a skill whose stated purpose is internet-search guidance creates unnecessary access to a high-risk capability. Even without explicit exploit code, this expands the attack surface by normalizing shell execution in contexts where user intent does not require it, making prompt injection or operator confusion more dangerous.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Claiming file read/write behavior for an internet-search guidance skill is an unjustified expansion of capability that can expose local data or enable unintended modification of workspace content. In this context, the mismatch between purpose and capability makes it easier for an agent to access files under the pretense of helping with search-related tasks.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documentation first says the skill is not suitable for complex needs, then later markets advanced automation, semantic processing, and knowledge-graph-style capabilities. This contradiction weakens operator understanding of the skill’s real behavior and can lead to unsafe delegation, over-trust, or invocation in contexts beyond its validated scope.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The activation guidance says to use the skill whenever the user needs internet-search-related functionality, but does not define boundaries, exclusions, or routing criteria precisely. Overly broad invocation criteria increase the chance that the skill is auto-selected in inappropriate contexts, especially given the presence of unjustified exec and file-related claims elsewhere in the skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.