Back to skill

Security audit

ApiFlash

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed OOMOL CLI connector skill whose main caution is an optional remote installer command, not hidden malicious behavior.

Install this only if you trust OOMOL and intend to use the connected service through its `oo` CLI. Before running the optional installer command, prefer official installation documentation, inspect the script first, or use a pinned package if available.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Content
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
Confidence
98% confidence
Finding
The skill instructs users to install software via `curl ... | bash`, which executes a remote script directly from the network without prior verification. If the distribution endpoint, TLS trust chain, DNS, or hosting account is compromised, this could lead to arbitrary code execution on the user's machine during setup.

Static analysis

No suspicious patterns detected.