Back to skill

Security audit

Clay

Security checks for vulnerabilities and agentic risk

Overview

This Clay connector skill is coherent and disclosed, with one setup command users should review before running.

Install only if you intend to use OOMOL's oo CLI with Clay. Before running the setup installer commands, review the installer source or use OOMOL's safer documented installation path if available. Confirm payloads carefully for actions tagged write or destructive because they can change Clay state or trigger downstream mutations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell, which executes unverified code from the network without integrity checking or review. If the install endpoint, transport, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Clay request," covering reading, creating, updating, and deleting data. That trigger scope is extremely broad and lacks exclusion conditions or narrower activation criteria, increasing the chance the skill is invoked for loosely related mentions of Clay.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.