rival-search-mcp-1a9cc2 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited rival-search-mcp-1a9cc2 (Agent Skill) and scored it 91/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You have access to 9 research tools via the CLI at scripts/cli.py. Run all commands with uv run scripts/cli.py.
Every tool returns deterministic, auditable output. There is no in-server LLM — you're the one doing the synthesis.
uv run scripts/cli.py call-tool <tool_name> --flag valueweb_search — concurrent search across DuckDuckGo, Bing, Yahoo, Mojeek, Wikipedia. Use for general web queries.social_search — Reddit, Hacker News, Stack Overflow, Dev.to, Medium, Product Hunt, Bluesky, Lobste.rs, Lemmy. Use for community discussions.news_aggregation — Google News, Bing News, The Guardian, GDELT, DuckDuckGo News. Use for current events. Accepts --time-range day|week|month|anytime.github_search — search public GitHub repos. Use for code, libraries, projects.map_website — crawl a site in research / docs / map mode. Use to explore site structure or documentation.content_operations — one tool, six ops (retrieve, stream, analyze, extract, score, find_conflicts). Use to get full page content, rate source quality, or surface disagreements between sources.document_analysis — extract text from PDFs, Word docs, images (image OCR via EasyOCR). Use for document processing.research_topic — end-to-end research workflow for a topic, combining search, content retrieval, and analysis.scientific_research — OpenAlex, CrossRef, arXiv, PubMed, Europe PMC (papers) + Kaggle, HuggingFace, Dataverse, Zenodo (datasets).content_operations --operation retrieve --url <url>content_operations --operation score --urls '[…]'content_operations --operation find_conflicts --urls '[…]'document_analysis --url <url>map_website --url <url> --mode docsresearch_topic --mode entity --topic "OpenAI"For full flags, types, and defaults for each tool, read:
All tools return structured text to stdout. Errors go to stderr. Exit codes: 0 success, 1 tool error, 2 connection failed.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.