Back to skill

Security audit

多搜索引擎免费版

Security checks across malware telemetry and agentic risk

Overview

This is a search-link skill that may open browser searches, so users should avoid entering confidential queries they do not want sent to public search engines.

Install only if you want an agent to generate or open public search-engine URLs. Do not use it with secrets, internal project names, private error logs, credentials, or other sensitive text unless you are comfortable sending that text to the chosen search provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The skill includes behavior to automatically open externally generated URLs in the user's browser via open/xdg-open. In this context, queries may contain sensitive user input and are sent to third-party search engines without a prominent warning or explicit confirmation, creating a privacy and unintended external-action risk.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger conditions are broad enough that the skill could activate for SEO optimization, ranking, and traffic-improvement requests, which are adjacent to potentially manipulative or policy-sensitive behavior. Overbroad activation increases the chance the agent invokes this skill in contexts where external searches or browser-launching actions are unnecessary or inappropriate.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples can open external search URLs and send the user's query to third-party search engines, but the skill lacks a clear, up-front warning about this disclosure. In a search skill, this context matters because user queries may contain confidential project names, internal errors, credentials, or other sensitive strings that should not be transmitted externally by default.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:85