ddg-search
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the DuckDuckGo API and returns it to the agent, creating a surface for indirect prompt injection.
- Ingestion points: External search results fetched via
curlfromapi.duckduckgo.cominscripts/search.sh. - Boundary markers: None; results are returned as plain text to the agent's context.
- Capability inventory: The skill utilizes
curlfor network access,jqfor parsing, andpython3for URL encoding. - Sanitization: None; the script extracts text fields (
AbstractText,RelatedTopics) and outputs them directly. - [METADATA_POISONING]: There is a documentation mismatch between the skill definition and the provided files.
- Evidence:
SKILL.mdrefers to a script namedsearch.py, while the actual implementation provided isscripts/search.sh.
Audit Metadata