Back to skill

Security audit

Datadog

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for read-only Datadog access, but it routes monitoring data through OOMOL, broadly directs all Datadog work through that connector, and documents unsafe remote installer commands.

Install only if you intentionally want Datadog queries and results routed through OOMOL. Use a dedicated read-only Datadog key with minimum scopes, review OOMOL's credential and data-handling controls, and avoid running the documented remote installer commands unless you can verify the installer source and integrity.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:15
Finding

Datadog Requests and Operational Data Are Routed Through a Third-Party Connector

Content
View full analysis
" ``` ```bash oo connector run "datadog" --action "" --data '' --json ``` ```text https://console.oomol.com/app-connections?provider=datadog ``` ### Technical Analysis The Skill does not access Datadog directly. It instructs users to connect Datadog to OOMOL and then submits action names, JSON request payloads, and connector results through OOMOL's infrastructure. OOMOL also controls server-side use of the connected Datadog credentials. Network communication is required to query Datadog, but introducing an intermediary expands the trust boundary beyond Datadog itself. Depending on the requested action, submitted and returned information may contain metric names, monitor definitions, infrastructure identifiers, tags, query expressions, timeseries values, or API-key validation results. The audited project does not document credential storage properties, data retention, operator access, tenant isolation, encryption controls, or the exact Datadog scopes granted to the intermediary. No direct evidence of credential theft or intentional exfiltration was found; the risk arises from third-party delegation and insufficiently documented least-privilege controls. ### Attack Path 1. A user connects a Datadog API key to an OOMOL account. 2. OOMOL obtains the server-side capability to issue requests under the connected credential's permissions. 3. The agent invokes `oo connector run` with a Datadog action and JSON parameters. 4. OOMOL receives an ...[truncated 935 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:3
Finding

Broad Instruction Forces All Datadog Requests Through the Vendor Connector

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a network-fetched shell script piped directly to bash, which executes remote content without prior verification. If the install endpoint, transport, or upstream distribution is compromised, this can lead to arbitrary code execution on the host running the skill setup.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Datadog request" and "Whenever a task involves Datadog," which is a very broad activation condition. It does not clearly bound when the skill should or should not be invoked, nor provide exclusions or negative examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.