Back to skill

Security audit

搜索助手免费版

Security checks across malware telemetry and agentic risk

Overview

This is mostly a web-search research helper, but it requests broad local file and command tools and has unclear SEO, callback, and capability instructions that should be reviewed before use.

Install only if you are comfortable with a search skill that may send your queries and generated subqueries to external search or fetch services. Review or narrow the requested read/exec/glob/grep authority, avoid using it with confidential prompts, and treat the SEO/ranking trigger language as outside the core research use case.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a search-task decomposition tool, but the documentation introduces generic create/query/export operations via `input_params` without defining strict schemas or boundaries. That mismatch can cause an agent to overgeneralize the skill's authority and perform unintended actions or expose data through unsupported workflows.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The document says result aggregation includes relevance scoring, while earlier sections explicitly state result quality scoring is not supported. This inconsistency can mislead downstream agents or users into trusting fabricated ranking metadata, increasing the risk of unsafe automation decisions based on nonexistent evaluation logic.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The trigger guidance recommends using the skill for SEO optimization, keyword analysis, ranking improvement, and search-traffic optimization, which conflicts with the stated research-assistant purpose and even sits near disallowed search-engine manipulation use cases. This broadens the skill into potentially abusive domains and may cause agents to invoke it for manipulative or policy-sensitive tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is overly broad and inconsistent with the actual capabilities, increasing the chance that an orchestrating agent invokes the skill in the wrong context. Mis-triggering matters here because the skill can drive web searches and aggregation, potentially sending user queries externally when another safer local tool should have been used.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill describes network search and an optional callback URL but does not clearly warn that user queries, derived subqueries, and possibly result metadata may be transmitted to external services. This creates a real privacy and data-handling risk, especially if sensitive research topics or internal information are included in prompts and then sent to search providers or callback endpoints.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.