ddg-search

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the DuckDuckGo API and returns it to the agent, creating a surface for indirect prompt injection.
  • Ingestion points: External search results fetched via curl from api.duckduckgo.com in scripts/search.sh.
  • Boundary markers: None; results are returned as plain text to the agent's context.
  • Capability inventory: The skill utilizes curl for network access, jq for parsing, and python3 for URL encoding.
  • Sanitization: None; the script extracts text fields (AbstractText, RelatedTopics) and outputs them directly.
  • [METADATA_POISONING]: There is a documentation mismatch between the skill definition and the provided files.
  • Evidence: SKILL.md refers to a script named search.py, while the actual implementation provided is scripts/search.sh.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:01 AM
Security Audit — agent-trust-hub — ddg-search