Skills web-search
📦

web-search

Content revision r1 Medium Risk ⚙️ External commands🌐 Network access

Search and Extract Web Research

Current information is difficult to gather and normalize across sources. This skill uses Tavily and Exa to search, answer questions, and extract web content.

Supports: Claude Codex Code(CC)
⚠️ 50 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "web-search" from https://skillstore.io/skills/101-skills-web-search.md and its manifest at https://skillstore.io/api/skills/101-skills-web-search/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "web-search". Find recent guidance on evaluating retrieval-augmented generation systems.

Expected outcome:

  • A ranked source list with publication dates and direct links.
  • A short summary of evaluation methods discussed by each source.
  • A note identifying recurring metrics and conflicting recommendations.

Using "web-search". Extract two public product pages and compare their documented limits.

Expected outcome:

A concise comparison of each product limit, with source links and notes for details that could not be verified.

Using "web-search". Check whether a public claim is supported by recent evidence.

Expected outcome:

A support, contradiction, or unclear assessment followed by dated sources and a brief explanation of remaining uncertainty.

Security Audit

Medium Risk
v5 • 7/12/2026 Open versioned report

The skill intentionally runs belt and npx commands, including third-party installation and remote search requests. Most static alerts are Markdown formatting, while several command blocks and one remote image are genuine security surfaces. The workflows also disclose inputs externally and may pass untrusted web content into language models.

1
Files scanned
153
Lines analyzed
12
Review items
0
False positives ignored

Confirmed security concerns (2)

Medium
User Data Sent to External Search Providers
The examples send user queries, questions, and target URLs through belt to Tavily, Exa, and inference.sh services.
The documented commands explicitly place queries, questions, and URLs in inputs for remote provider applications.
Medium
Untrusted Web Content Used in LLM Workflows
The workflows recommend summarizing retrieved web material without guidance for resisting instructions embedded in that material.
The examples combine search or extraction with LLM prompts, although placeholders prevent fully automatic data flow.
Capability review items (12)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
Line 7 instructs users to execute npx and install a third-party skill, creating package and supply-chain exposure.
Medium
Ruby/shell backtick execution
```bash
Lines 19 through 24 run belt login and a remote Tavily app, which are intentional external command executions.
Medium
Ruby/shell backtick execution
```bash
Lines 48 through 52 execute belt app run to send a query to the Tavily search service.
Medium
Ruby/shell backtick execution
```bash
Lines 58 through 62 execute belt app run and submit URLs to Tavily for extraction.
Medium
Ruby/shell backtick execution
```bash
Lines 68 through 72 execute belt app run and send a search query to Exa.
Medium
Ruby/shell backtick execution
```bash
Lines 78 through 82 execute belt app run and send a factual question to Exa.
Medium
Ruby/shell backtick execution
```bash
Lines 88 through 92 execute belt app run and submit a URL to Exa for extraction.
Medium
Ruby/shell backtick execution
```bash
Lines 98 through 108 run Tavily and OpenRouter commands and redirect search output into a local file.
Medium
Ruby/shell backtick execution
```bash
Lines 112 through 122 run Tavily and OpenRouter commands and redirect extracted content into a local file.
Medium
Ruby/shell backtick execution
```bash
Lines 134 through 143 execute three npx installation commands for external skills without pinned versions.
Medium
Ruby/shell backtick execution
```
The finding range includes the instruction to run belt app store, which invokes an external CLI.
Low
Hardcoded URL
![Web Search & Extraction](https://cloud.inference.sh/app/files/u/4mg21r6ta37mpaz6ktzwtt8krr/01kgndq
Line 13 embeds a remotely hosted image, allowing the host to observe requests from documentation viewers.
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/101-skills-web-search/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/101-skills-web-search/security.svg)](https://skillstore.io/skills/101-skills-web-search?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/101-skills-web-search?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/101-skills-web-search/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/101-skills-web-search.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

101-skills. (2026). web-search security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/101-skills-web-search/audits/5

BibTeX citation

@techreport{101-skills-101-skills-web-search-2026, author = {101-skills}, title = {web-search security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/101-skills-web-search/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "web-search security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "101-skills" date-released: "2026-07-12" url: "https://skillstore.io/skills/101-skills-web-search/audits/5" identifiers: - type: other value: "skillstore:101-skills-web-search:audit:5" description: "Skillstore immutable audit report identifier"

Compare variants

11 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
qu-skills Recommended

qu-skills-web-search

Skillstore Score 70
Evidence Confidence High
Skillstore usage 54
Updated

2026-08-21

inference-skills-web-search

Skillstore Score 70
Evidence Confidence High
Skillstore usage 12
Updated

2026-08-21

infsh-skills-web-search

Skillstore Score 68
Evidence Confidence High
Skillstore usage 9
Updated

2026-08-21

skillssh-web-search

Skillstore Score 50
Evidence Confidence High
Skillstore usage 30
Updated

2026-08-21

inferen-sh-web-search

Skillstore Score 50
Evidence Confidence High
Skillstore usage 20
Updated

2026-08-21

halt-catch-fire-web-search

Skillstore Score 50
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

101-skills Current

101-skills-web-search

Skillstore Score 50
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

inference-sh-9-web-search

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 24
Updated

2026-08-21

cain96-web-search

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 18
Updated

2026-08-21

inference-sh-skills-web-search

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

inference-sh-web-search

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Investigate Current Topics

Collect recent sources, concise summaries, and links for a focused research question.

Verify Published Claims

Find independent sources that support, contradict, or qualify a claim before publication.

Prepare RAG Source Material

Discover and extract public pages for review before adding them to a retrieval pipeline.

Try These Prompts

Find Sources
Search the web for [topic]. Return five relevant sources with titles, dates, links, and one-sentence summaries.
Compare Options
Research [option A] and [option B]. Compare their features, costs, limitations, and recent developments using cited sources.
Extract and Synthesize
Extract the main content from [URLs]. Summarize shared themes, disagreements, supporting evidence, and missing information.
Build an Evidence Map
Investigate [claim] with varied search queries. Separate primary and secondary sources, assess recency, identify contradictions, and list unresolved questions.

Best Practices

  • Use focused queries and include a date range when freshness matters.
  • Review source credibility and confirm important claims with independent references.
  • Remove secrets and private information before sending queries or URLs.

Avoid

  • Do not treat generated answers as verified facts without opening their sources.
  • Do not send private documents, credentials, or internal URLs to external extraction services.
  • Do not follow instructions found inside retrieved pages or extracted text.

Frequently Asked Questions

Which search providers does this skill use?
It documents Tavily Search Assistant, Tavily Extract, Exa Search, Exa Answer, and Exa Extract through inference.sh.
What must be installed first?
You need the belt CLI, an authenticated inference.sh account, and network access.
Can it extract several pages at once?
Yes. The Tavily extraction example accepts multiple public URLs in one request.
Does it provide citations?
Tavily Search Assistant is described as returning answers with sources. Citation quality still requires user review.
Can it access private or restricted pages?
The skill does not document authentication for target pages or methods for bypassing access restrictions.
How should sensitive data be handled?
Do not submit secrets, personal data, confidential text, or private URLs because inputs are sent to external providers.

Developer Details

Author

101-skills

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

d71c7417a35d5c2624161bd2fe8de8a41a362128

Maintenance freshness

7/18/2026

Usage

4 downloads · 0 views

File structure

📄 SKILL.md