Back to skill

Security audit

搜索引擎

Security checks for vulnerabilities and agentic risk

Overview

The skill is framed as a search helper but asks for broad local file and command-execution authority without clear scope or user controls.

Review carefully before installing. Use this only in a sandbox or with command execution and local file access disabled unless the publisher narrows the scope. Avoid entering secrets, private file contents, or credentials into search queries, and do not run the agent as administrator for this skill.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:35
Finding

Search Skill Requests Unnecessary Filesystem and Command-Execution Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35-39
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - glob
  - grep

Technical Analysis

The Skill's declared purpose is to submit queries to public search engines and aggregate search results. This functionality requires narrowly scoped outbound HTTPS access, but it does not inherently require arbitrary command execution or general access to the local filesystem.

The exec capability permits system-command execution, while read, glob, and grep allow discovery and inspection of local files. These permissions exceed the minimum privileges required for web search. The documentation further advertises generic file processing and command execution at SKILL.md:238-240, and advises running with administrator privileges when permissions are insufficient at SKILL.md:275. These instructions unnecessarily increase the potential effect of misuse.

The Markdown file does not contain an explicit malicious command, automatic credential theft, or a direct mechanism that executes a remote payload. The vulnerability is therefore an overprivileged capability declaration rather than evidence of intentional malware.

The network examples at SKILL.md:155 and SKILL.md:167 submit search queries to Google and DuckDuckGo. Sending query text to a selected search provider is necessary for the declared functionality, and no confirmed API-key exfiltration path was identified. Nevertheless, users could place confidential information in a query, so query transmission should be disclosed and constrained.

Attack Path

  1. A user installs or loads the Skill on an Agent platform that grants the tools declared in SKILL.md.
  2. The Agent receives read, glob, grep, and exec authority even though only network retrieval is needed for search.
  3. An attacker ...[truncated 1452 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, glob, and grep from the declared tools unless a concrete, documented search feature requires each capability.
  2. Grant only a narrowly scoped HTTPS-fetching tool with an allowlist of supported search-engine domains.
  3. Remove the generic file-processing and command-execution claims at SKILL.md:238-240.
  4. Remove the administrator-execution recommendation at SKILL.md:275. The Skill should fail safely when permissions are insufficient rather than request elevation.
  5. Require explicit user confirmation before sending each query to an external provider, particularly when a query may contain personal, proprietary, or credential-like data.
  6. URL-encode query parameters and validate the selected engine against a fixed allowlist. Do not permit arbitrary schemes, hosts, redirects, or user-supplied executable commands.
  7. Document exactly which external providers receive query content and establish a policy that prohibits submitting secrets, API keys, private file contents, or authentication material.
  8. If local caching is later introduced, use a dedicated application directory with restrictive permissions and avoid storing raw sensitive queries.
  9. Enforce host-side sandboxing, deny shell access by default, and run the Agent under an unprivileged operating-system account.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented output schema is for a grading/evaluation report rather than search results, which conflicts with the stated purpose of the skill. This kind of semantic mismatch can cause downstream agents or users to trust incorrect behavior, mishandle outputs, or route data into unintended workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file inconsistently describes the skill as both pure Markdown/natural-language driven and as requiring executable capabilities. That ambiguity is dangerous because reviewers or execution frameworks may underestimate the operational risk and permit command execution under a lower-trust classification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a search-engine integration, but later broadens its capabilities to file handling, API integration, and command execution. This mismatch can mislead users and agent platforms into granting or exercising higher-risk behaviors than expected, increasing the chance of unsafe execution under a benign-looking label.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises file handling capabilities in a search-oriented package without clearly warning users that local data may be modified. In an agent context, understated write-capable behavior can lead to unexpected alteration of user files, workflow corruption, or persistence of unintended artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises command execution without an explicit user-facing warning, which is especially risky because the skill is branded as a search tool rather than a system-execution tool. In this context, hidden or underexplained execution capability materially raises the chance of arbitrary or system-impacting actions being taken with insufficient scrutiny.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The FAQ states that the skill '会自动聚合和去重搜索结果', which describes concrete behavior beyond simple search invocation. In this file, there is no corresponding logic, workflow, or instructions implementing aggregation or deduplication, making the claim contradict the apparent content of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.