Back to skill

Security audit

serper-v

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed Serper search CLI wrapper, but users should treat its unpinned global npm install and API-key setup as a supply-chain and credential-handling caveat.

Before installing, prefer a pinned reviewed version, avoid --force if possible, and use a revocable Serper API key with limited quota. Check where serperV stores credentials and remove the global package if you no longer need the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Global Installation of a Third-Party CLI

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-26; duplicated without the force option in SETUP.md:3-10
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

Complete vulnerable code snippets (SKILL.md:24-26):

bash
## Setup
1. `npm install -g @vinitngr/serper-v --force`
2. `serperV auth <api_key>`

Related code snippet (SETUP.md:3-10):

bash
### 1. Global Install
npm install -g @vinitngr/serper-v

### 2. Set API Key
serperV auth YOUR_API_KEY_HERE

Technical Analysis

The setup instructions install @vinitngr/serper-v globally without pinning an exact version or providing an integrity value. Consequently, the package resolved at installation time can differ from the version originally reviewed. The --force option in SKILL.md further weakens npm safeguards.

The artifact contains only documentation and does not include the dependency's source, a lockfile, or integrity metadata. Its lifecycle scripts, credential-storage behavior, executable logic, and outbound network destinations therefore cannot be verified from the reviewed project. The subsequent authentication command supplies a Serper API key to that unaudited CLI.

This finding does not establish that the current package is malicious. It identifies a supply-chain exposure in which a compromised maintainer account, malicious future release, or registry compromise could turn the documented installation process into a code-execution and credential-theft vector.

Attack Path

  1. An attacker compromises the package publisher, registry distribution path, or a future release of @vinitngr/serper-v.
  2. The attacker publishes a malicious package version containing harmful lifecycle scripts or CLI behavior.
  3. A user follows the documented unpinned npm install -g command, which resolves the attacker-controlled release.
  4. npm installs the package globally and ma ...[truncated 1013 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version rather than resolving the latest release:
    bash
    npm install --save-exact @vinitngr/serper-v@REVIEWED_VERSION
    
  2. Prefer a project-local installation over npm install -g, and invoke it through a controlled package script or an explicitly pinned local binary.
  3. Remove --force so npm's normal protections and conflict checks remain enabled.
  4. Commit a lockfile containing resolved versions and integrity hashes, and verify package provenance and signatures where supported.
  5. Review the package source and all lifecycle scripts before recommending installation. Consider disabling lifecycle scripts during installation when they are unnecessary:
    bash
    npm install --ignore-scripts
    
  6. Document where serperV auth stores credentials, the filesystem permissions applied to them, and every expected network endpoint.
  7. Use a narrowly scoped, revocable API key and avoid exposing it in shell history, logs, process arguments, or plaintext configuration.
  8. Add dependency monitoring and require a fresh security review before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.