searxng
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a web search specialist, requiring the agent to retrieve and process untrusted data from various search engine categories (general, it, science, etc.). This creates a vulnerability surface where malicious instructions embedded in web search results could attempt to override the agent's behavior during the synthesis phase.
- Ingestion points: External web content and search results retrieved via the SearXNG metasearch engine (SKILL.md).
- Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters or to treat ingested content as untrusted data that should not be followed as instructions.
- Capability inventory: The skill itself does not define tool code, but it provides instructions for using metasearch capabilities which inherently interact with the agent's search and summary tools.
- Sanitization: Absent; no instructions are provided to sanitize, filter, or validate the content of the search results before the agent synthesizes them for the user.
Audit Metadata