curl-search
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content retrieved from external search engines, which creates a potential surface for indirect prompt injection attacks where malicious instructions hidden in web pages could influence agent behavior.
- Ingestion points: The
scripts/search.shscript usescurlto fetch live data from Baidu, Google, Bing, and DuckDuckGo based on user queries. - Boundary markers: There are no explicit boundary markers or instructions telling the agent to treat the fetched search results as untrusted content.
- Capability inventory: The skill possesses network access capabilities via
curland local execution capabilities viapython3. - Sanitization: The script includes basic sanitization that uses
sedto strip HTML tags from the retrieved search results before they are echoed to the agent. - [DYNAMIC_EXECUTION]: The skill uses a dynamic execution pattern to perform URL encoding by interpolating user-provided strings into a Python command.
- Evidence: The
encode_urlfunction inscripts/search.shcallspython3 -c "import urllib.parse; print(urllib.parse.quote('$input', safe=''))". - Mitigation: This execution pattern is significantly mitigated by the
sanitize_inputfunction, which is called prior to encoding and removes single quotes and other special characters that could be used to break out of the Python string literal.
Audit Metadata