searxng

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is comprised entirely of Markdown files (SKILL.md and reference documents). It does not include any scripts, executables, or code files, which eliminates the possibility of direct malicious execution from the skill itself.
  • [SAFE]: No patterns of prompt injection, data exfiltration, or obfuscation were detected. The search queries and technology examples provided (Laravel, Nuxt, Rust, Docker) are standard and appropriate for a development-focused search utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that involves ingesting and processing content from external web sources via search results. This presents a potential surface for indirect prompt injection, as adversarial content from the internet could contain instructions intended to influence the agent.
  • Ingestion points: Data enters the agent's context from multiple external search engines (Google, Bing, DuckDuckGo) and community sites (GitHub, Stack Overflow) through SearXNG.
  • Boundary markers: The documentation does not define specific boundary markers or instructions to isolate or ignore potential commands embedded within search results.
  • Capability inventory: The skill identifies 'debug' and 'error-resolution' as related skills, implying the agent may possess diagnostic or code execution capabilities that could be influenced by external input.
  • Sanitization: The skill does not provide instructions for sanitizing or validating the integrity of the data retrieved from search results before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:28 PM
Security Audit — agent-trust-hub — searxng