serpapi
Fail
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: CRITICALNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown files providing instructions and reference schemas. It does not include any scripts, binaries, or active code components.
- [SAFE]: The external service described (
serpapi.com) is a well-known provider of search engine scraping tools for developers. The skill's purpose is to enable standardized access to this service. - [EXTERNAL_DOWNLOADS]: While the skill mentions the SerpApi endpoint, it does not trigger any automated downloads, installations, or execution of remote scripts. References to the external API documentation are informational.
- [DATA_EXFILTRATION]: No exfiltration patterns were found. The instructions appropriately guide the agent to provide an
api_keyto the legitimate service endpoint for authentication during requests. - [PROMPT_INJECTION]: The skill instructs the agent to ingest and display external data from search results. This introduces a potential surface for indirect prompt injection (where malicious content on a web page could try to override the agent's instructions), but this is an inherent risk of any search-enabled AI capability and is not an intentional vulnerability in the skill itself.
- Ingestion points: Data retrieved from SerpApi endpoints as described in
SKILL.mdand reference files. - Boundary markers: None explicitly defined in the provided instruction set.
- Capability inventory: No code-based execution capabilities are present within the skill.
- Sanitization: No specific content sanitization or escaping instructions are provided for the incoming data.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata