serp-analysis

Fail

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell command template (curl ... | python3 -c "...") for automated search analysis. This template is highly vulnerable to command injection if the {query} or {key} placeholders are substituted with unsanitized user input, potentially allowing execution of arbitrary system commands (e.g., via backticks, subshells, or semicolon separators).
  • [REMOTE_CODE_EXECUTION]: Automated scanners detected a remote code execution pattern involving curl piped to python3. While the skill currently pipes to a local Python script via python3 -c, the combination of network data and shell execution poses a high risk if the data stream or command arguments are manipulated.
  • [DYNAMIC_EXECUTION]: The skill uses python3 -c to execute an inline Python script block defined within the markdown to process search data. This involves runtime execution of code strings provided in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: Fetches search engine data from SerpAPI, an external search engine results provider. This involves automated network requests to retrieve content for analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze search engine results (SERPs) from Google. Since search results are external and controlled by third parties, they could contain adversarial content intended to manipulate the agent's logic during the parsing or reporting phase.
Recommendations
  • HIGH: Downloads and executes remote code from: https://serpapi.com/search?q={query}&engine=google&api_key={key} - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 18, 2026, 10:25 PM
Security Audit — agent-trust-hub — serp-analysis