Back to plugin

Security audit

Web Search Plus

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed web search and extraction plugin that uses configured external providers and an optional local DonSeTch executable with clear opt-in controls.

Before installing, decide which optional tools and providers the agent actually needs. Queries and URLs may be sent to the configured providers, TinyFish has a documented data-use warning, and DonSeTch should only be enabled after separately reviewing and testing that local executable.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:1008
Evidence
for (const [key, value] of Object.entries(process.env)) {