Back to skill

Security audit

多搜索引擎工具免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is a search helper, but it asks for broad local file and command tools and is unclear about active browsing and third-party query sharing.

Review this before installing. Use it only for searches you are comfortable sending to third-party search engines, avoid secrets or sensitive internal topics, and do not approve shell commands or callback URLs unless you understand what data will be sent and why.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill claims it only generates links and does not automatically fetch or aggregate results, yet examples instruct the agent to open engines, retrieve results, compare them, and even compute answers. This mismatch can cause the agent to perform more network activity and third-party data disclosure than the user or platform expects, weakening trust boundaries and consent around browsing and result processing.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill declares read, exec, glob, and grep even though its stated purpose is search-link generation and comparison. Overbroad local tooling materially increases attack surface because a prompt-influenced skill handling untrusted search terms could be induced to inspect local files, execute shell commands, or enumerate sensitive workspace content unrelated to the user's search request.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill does not warn users that queries may be sent to third-party search engines and that callback URLs may receive data. This creates a privacy and data-governance risk because users may provide sensitive research terms, identifiers, or internal topics without realizing they will be transmitted outside the local agent context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.