Back to skill

Security audit

CUFinder

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for CUFinder lookups, but its setup path includes unverified remote shell-install commands that should be reviewed before use.

Before installing, review the OOMOL CLI installer through official documentation and prefer a verified package or manually inspected installer. Use this skill only for intended CUFinder enrichment/lookups, and be aware that person/email enrichment may return sensitive contact data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI via a remote script piped directly into a shell (curl ... | bash), which creates a supply-chain and arbitrary code execution risk if the install endpoint, transport, or upstream distribution is ever compromised. In a skill context, this is more dangerous because the content explicitly tells an agent/operator to run the command as part of setup, turning documentation into a high-trust execution path.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use this skill for "ANY CUFinder request," which is a broad activation condition without examples or constraints on what counts as a CUFinder request. This can cause unintended invocation whenever CUFinder is merely mentioned, rather than only when the user explicitly wants connector-backed actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.