google-search

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script google_search.py contains a hardcoded demo access key 'BETA_TEST_KEY_MARCH_2026' as a fallback when no environment variable is provided.
  • [COMMAND_EXECUTION]: The script reads local files if a path is passed to the --data-file argument, a common CLI pattern for processing input.
  • [DATA_EXFILTRATION]: Tool data is transmitted to the vendor's router at deepnlp.org via the ai_agent_marketplace library, which is a verified vendor resource.
  • [PROMPT_INJECTION]: The skill ingests external data from Google search results, creating a surface for indirect prompt injection that requires handling by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 08:46 AM
Security Audit — agent-trust-hub — google-search