skills/clawlink-hq/skills/serpapi/Gen Agent Trust Hub

serpapi

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on the @useclawlink/cli package, which is downloaded and executed via npx. This is a vendor-owned package used for the tool's core functionality.- [COMMAND_EXECUTION]: The skill requires executing shell commands using the npx utility to perform authentication, connection, and search operations.- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from various external search engines (Baidu, Bing, DuckDuckGo, etc.). This content could potentially contain instructions designed to influence the AI agent's behavior.
  • Ingestion points: Multiple search actions in SKILL.md (e.g., serpapi_baidu_search, serpapi_bing_search, serpapi_duck_duck_go_search).
  • Boundary markers: No delimiters or specific 'ignore instructions' warnings are provided for the search result data.
  • Capability inventory: The agent has the ability to execute shell commands via the @useclawlink/cli tool.
  • Sanitization: No sanitization or filtering of the external search content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:43 PM
Security Audit — agent-trust-hub — serpapi