Back to skill

Security audit

ClickSend

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing ClickSend through OOMOL, but it asks for broad CLI authority and includes unsafe first-time installer commands.

Review before installing. The ClickSend workflow is disclosed and includes confirmation for state-changing actions, but users should avoid running the pipe-to-shell installer as written unless they trust and can verify the OOMOL installer. The publisher should narrow tool permissions to ClickSend connector commands and document safer installation steps with versioning or verification.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:67
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis
Remediation
View remediation
' 'oo-install.sh' | sha256sum --check - less oo-install.sh bash oo-install.sh ``` 7. Avoid requiring administrator privileges unless a documented installation target strictly requires them. 8. Prefer established, signed platform package managers where available. 9. Ensure automated agents do not install software without explicit user authorization. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:4
Finding

Overbroad Wildcard Authorization for All oo CLI Subcommands

Content
View full analysis
" oo connector run "clicksend" --action "" --data '' --json ``` However, the authorization pattern `Bash(oo *)` permits every command and subcommand exposed by the `oo` executable, rather than limiting execution to the required ClickSend connector operations. This includes unrelated current subcommands and any additional subcommands introduced by future CLI versions. The documentation advises the agent not to run `oo auth login` proactively and requires confirmation for write or destructive connector actions. Those textual safeguards reduce accidental use but do not technically enforce the least-privilege boundary. If untrusted task content, connector data, or prompt manipulation causes an unintended command to be constructed, the broad wildcard may authorize it as long as it begins with `oo`. ### Attack Path 1. The skill is loaded with permission to execute any command matching `oo *`. 2. An attacker supplies malicious or misleading instructions through user-controlled task content or other content processed by the agent. 3. The agent is induced to invoke an unrelated `oo` subcommand rather than one of the documented ClickSend operations. 4. The wildcard authorization accepts the command because it begins with `oo`. 5. The command executes using the local user's OOMOL session and whatever account permissions are available to that CLI. 6. The attacker may obtain unintended account information or cause actions outside the ClickSend-specific scope, depending on the installed CLI's available commands and the user's au ...[truncated 864 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs use of a remote installation script via curl ... | bash, which executes code fetched from the network without verification. If the install endpoint, transport, or hosting environment is compromised, this becomes an immediate arbitrary code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text says to use this skill for "ANY ClickSend request" and for any task involving ClickSend instead of calling the API directly. That broad routing can cause the agent to invoke this skill for all ClickSend-related tasks, including sensitive write or destructive operations, increasing the chance of unintended execution if user intent is ambiguous or if safer alternatives exist.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.