Back to skill

Security audit

Free Web Search Ultimate

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent web-search helper, but it needs review because it recommends broad external searching and an unpinned executable MCP install from GitHub.

Review before installing. Use a pinned and reviewed revision if possible, install it in an isolated environment, and avoid enabling this skill for prompts containing secrets, proprietary information, internal URLs, or private documents unless you are comfortable sending derived queries or URLs to external services.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:113
Finding

Unpinned Remote Git Dependency Used as an Executable MCP Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 113–130
Vulnerability Type: Supply-chain exposure through an unpinned remote dependency
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "free-web-search": {
      "command": "free-web-search-mcp",
      "args": []
    }
  }
}
bash
pip install git+https://github.com/wd041216-bit/free-web-search-ultimate.git

Technical Analysis

The documented installation command installs a Python package directly from a mutable GitHub repository without specifying an immutable commit, version tag, package hash, or signature verification. Package installation may execute attacker-controlled build logic. After installation, the resulting free-web-search-mcp executable is registered as an MCP server and may be launched by the desktop client.

Because the repository reference is unpinned, the code installed by users can differ from the code that was originally reviewed. Compromise of the upstream repository, maintainer account, or release process could therefore introduce arbitrary executable code into the installation path.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or another component of its publishing workflow.
  2. The attacker adds malicious package build logic or modifies the free-web-search-mcp executable.
  3. A user follows the documented unpinned pip install git+https://... command.
  4. Pip retrieves the current attacker-controlled repository contents and runs applicable package build or installation logic.
  5. The user adds the documented MCP configuration.
  6. Claude Desktop, Cursor, or another compatible client launches free-web-search-mcp, executing the modified code under the user's account.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user who installs or launches the MCP server. Dep ...[truncated 407 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an audited immutable commit SHA or a specifically reviewed signed release rather than the repository's mutable default branch.
  • Prefer a reproducible package artifact with cryptographic hashes, and enforce hash verification during installation.
  • Verify release signatures or provenance attestations where available.
  • Pin and audit transitive dependencies, including the listed Python requirements.
  • Document the exact repository revision and dependency set covered by the security review.
  • Install and run the MCP server in a dedicated virtual environment or sandbox with minimal filesystem, credential, and network access.
  • Require users to review the resolved executable path and configuration before enabling the MCP server.
  • Establish a controlled update process that reviews and verifies new revisions before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

free-web-search-mcp`)

  • LangChain — via Python tool wrappers
  • OpenAI Function Calling — via JSON schema definitions

MCP Server Setup (Claude Desktop / Cursor)

Add to your claude_desktop_config.json:

json
{
  "mcpServers": {
    "free-web-search": {
      "command": "free-web-search-mcp",
      "args": []
    }
  }
}

Install via pip from the GitHub repository:

bash
pip install git+https://github.com/wd041216-bit/free-web-search-ultimate.git

Requirements

  • Python 3.8+
  • beautifulsoup4, lxml, ddgs, mcp>=1.1.2

License

MIT-0 — Free to use, modify, and redistribute. No attribution required.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill defines behavior for 'any LLM agent' and says the agent should follow the guidance whenever the skill is active, but it provides no narrow activation conditions, exclusions, or user-consent boundaries. In practice this can cause overbroad invocation, leading agents to search externally for many prompts by default and increasing the chance of unintended data disclosure or tool misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to send queries to live search and browse external pages, but it does not warn that user prompts, derived queries, URLs, and retrieved content may be transmitted to third-party services. This creates a privacy and data-handling risk because sensitive or proprietary information could be exposed outside the local environment without informed user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.