Back to skill

Security audit

Onimi Pages & Slides

Security checks for vulnerabilities and agentic risk

Overview

The skill’s sensitive Onimi cloud actions are disclosed, user-directed, and scoped to creating, saving, publishing, and sharing Onimi Pages or Slides.

Install only if you intend to let Onimi handle private drafts, publishing, and sharing for Pages or Slides. Review the OAuth scopes in the browser, keep controlled-sharing links private, and use the dashboard to revoke access when you no longer need the integration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (16)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
Before multi-step cloud writes, use `scripts/task-state.mjs` as described in

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
Before multi-step cloud writes, use `scripts/task-state.mjs` as described in
[publish.md](references/publish.md). Retain exact mutation IDs and fixed references
for uncertain retries; reconcile actual server receipts before claiming success.
Private source, credentials and one-time access secrets stay outside the Skill and Git.

Validate the complete artifact and audience before publishing. Keep controlled-cloud
works private. Report only the saved/published revision and access that the server

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/page-quality.md (reported line 9)May include surrounding context.

md
editorial reading path, anchored evidence, and a print layout.
- Operational material such as runbooks, plans, and itineraries benefits from sequence, progress, and
  locally persistent or clearly temporary check state.
- Comparison and calculation tools need explicit inputs, immediate results, sane defaults, and a clear
  statement that sample figures are illustrative.
- Teaching and quiz pages need visible progress, reversible choices, keyboard-complete controls, and
  feedback that explains the result.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/create.md (reported line 42)May include surrounding context.

md
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.

Updating keeps the same project, revisions, release history, visibility, grants and controlled data

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/publish.md (reported line 139)May include surrounding context.

md
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.

Updating keeps the same project, revisions, release history, visibility, grants and controlled data

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/publish.md (reported line 172)May include surrounding context.

md
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.

Updating keeps the same project, revisions, release history, visibility, grants and controlled data

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/publish.md (reported line 86)May include surrounding context.

md
original task. Report only observed stages, never a percentage. Verify with the least sensitive safe
read: call `onimi_get_connection` and compare its account and effective scopes. If an older deployed
service does not expose it, `onimi_list_projects` is a compatibility fallback and an empty list is
success. Do not read a private draft or create a project as a connection test. The connection tool's
`installedModules: "client-local-check-required"` means inspect the actual local Skill directory; never
infer installation from the server. If the user cancels, preserve the local artifact and these exact
continuation identifiers when present: `resourceType`, `resourceKey`, `resourceVersion`, `locale`, and

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/publish.md (reported line 114)May include surrounding context.

md
Before any project or release write, establish the target intent from the whole conversation: update
one existing project, or create one new project. A generic request to publish does not mean create a
new project. Reuse an explicit earlier choice of target, project name or access; do not ask the user to
confirm the same choice again.

Inspect the actual discovered input schema before using a project selector. When that tool

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/create.md (reported line 289)May include surrounding context.

md
that readback succeeds. A 409 means another save won; read and reconcile the new head. Never
change the body or expected revision while reusing an idempotency UUID.

For a small Slides source that the client can forward without truncation, `onimi_save_draft` is
also valid with the complete source, exact manifest, current revision and UUID. If saving returns
`INVALID_SOURCE`, inspect the actual source and manifest against the accepted schema; do not
silently drop resource provenance, create another project or claim that a local file is a saved

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/slides.md (reported line 194)May include surrounding context.

md
that readback succeeds. A 409 means another save won; read and reconcile the new head. Never
change the body or expected revision while reusing an idempotency UUID.

For a small Slides source that the client can forward without truncation, `onimi_save_draft` is
also valid with the complete source, exact manifest, current revision and UUID. If saving returns
`INVALID_SOURCE`, inspect the actual source and manifest against the accepted schema; do not
silently drop resource provenance, create another project or claim that a local file is a saved

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code throws unless locale is exactly "en" or "zh-CN", which enforces a narrow language/locale policy in code. This is a natural-language policy concern because the file does not offer user choice or document a region-specific justification for excluding other locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

该文件全文以中文撰写,未见提供语言选择、用户 opt-in,或说明这是仅面向特定中文用户群体的区域化版本。根据规则,强制特定语言而无选择可能构成语言/区域策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest defines only "zh-CN" and "en" under the locales section, which indicates the skill is constrained to specific languages. Under the policy criteria, forcing a specific language set without user opt-in or a documented regional justification can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest defines only zh-CN and en locale entries, which imposes a language constraint in the skill configuration. Under the policy, language or locale restrictions should either offer user choice or be clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code rejects any locale except "zh-CN" and "en" with an "Unsupported content locale" error. This is a natural-language locale restriction, and the file does not provide an opt-in mechanism or explain why the limitation is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.