Back to skill

Security audit

Deepgram

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Deepgram access through OOMOL, but it includes unsafe remote installer commands and broadly routes Deepgram data through a third-party connector.

Review before installing. Prefer installing the oo CLI through a verified package or manually inspected installer, use least-privilege Deepgram credentials, and be careful before listing project keys or sending sensitive project data through the OOMOL connector.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62-66
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

These installation commands retrieve mutable scripts from an external server and immediately pass their contents to Bash or PowerShell. They do not pin a version, validate a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded payload before execution.

HTTPS protects the connection in transit but does not guarantee that the hosted installer is safe or immutable. Compromise of the domain, hosting environment, CDN, deployment credentials, or installation script could cause arbitrary attacker-controlled code to execute. The effective payload can also change after the Skill has been reviewed.

Arbitrary shell execution exceeds the minimum permissions needed for the declared functionality, which is limited to invoking a Deepgram connector through an installed CLI.

Attack Path

  1. The oo CLI is unavailable on the target system.
  2. A user or agent follows the documented first-time setup instructions.
  3. An attacker compromises the installer distribution path or otherwise causes the remote endpoint to return a malicious script.
  4. curl or irm downloads the attacker-controlled content.
  5. The pipeline passes that content directly to Bash or PowerShell without integrity verification.
  6. The payload executes with the privileges of the user running the command.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. Depending on that account's privileges, the payload could read or alter accessible files, steal credentials and environment dat ...[truncated 179 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all download-and-immediately-execute installation commands.
  • Prefer an official package manager and pin the CLI to an audited version.
  • If a standalone installer is necessary, download it to a local file without executing it.
  • Publish and verify a cryptographic checksum or signature from an independent trusted channel before execution.
  • Allow users to inspect the downloaded script before running it.
  • Execute installation with ordinary user privileges unless a narrowly defined step explicitly requires elevation.
  • Pin installation URLs to immutable, versioned artifacts rather than mutable install.sh or install.ps1 endpoints.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:3
Finding

Universal Deepgram Request Redirection Through a Third-Party Intermediary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 3
Vulnerability Type: Agent instruction and tool-routing hijacking
Risk Level: Medium

Vulnerable Code

yaml
description: "Deepgram (deepgram.com). Use this skill for ANY Deepgram request — searching and reading data. Whenever a task involves Deepgram, use this skill instead of calling the API directly."

Related sensitive capability documented at SKILL.md:45:

markdown
- `list_project_keys` — List the API keys associated with a Deepgram project.

Technical Analysis

The Skill instructs the agent to route every Deepgram-related request through OOMOL instead of using the official API directly. This broad instruction changes agent tool selection beyond an explicit request to use the intermediary and adds OOMOL as another trust boundary for request and response data.

The intermediary is disclosed, and the document states that OOMOL injects credentials server-side, so the reviewed content does not demonstrate concealed credential theft. Nevertheless, the universal routing instruction is broader than necessary for read-only Deepgram access. The risk is increased by the documented list_project_keys operation, whose response may contain sensitive API-key information.

Attack Path

  1. A user submits any request involving Deepgram.
  2. The Skill's universal routing instruction causes the agent to use oo connector instead of a direct official Deepgram API integration.
  3. OOMOL receives or processes the connector request using server-side credentials.
  4. The response is returned through the intermediary and may include sensitive project metadata or API-key information.
  5. Sensitive data may consequently be exposed to an additional service boundary or included in agent output and associated logs.

Impact Assessment

This behavior expands the parties and infrastructure trusted with Deepgram data. Potentially affected information ...[truncated 336 chars]

Remediation
View remediation

Remediation Suggestions

  • Limit Skill activation to requests where the user explicitly chooses the OOMOL connector.
  • Do not mandate intermediary routing for every Deepgram-related request.
  • Clearly disclose what request and response data OOMOL processes before the first connector operation.
  • Permit direct use of the official Deepgram API where supported and authorized.
  • Remove list_project_keys if it is not essential to the declared functionality, or gate it behind explicit user confirmation.
  • Redact API-key values and other secrets from agent responses, telemetry, execution traces, and logs.
  • Apply least-privilege Deepgram credentials that expose only the projects, scopes, and read operations required for the current task.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a classic 'curl | bash' installation command that fetches and executes a remote script directly from the network. If the remote host, script distribution path, TLS trust, or supply chain is compromised, arbitrary code would execute on the user's machine with the privileges of the shell, making this especially dangerous in a tool-invoking agent context.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says to use this skill for ANY Deepgram request and instead of calling the API directly, which is an overly broad routing rule. That can cause the agent to invoke this skill in contexts it does not narrowly need, increasing exposure to tool execution, connector-side data access, and setup/install instructions that may not be appropriate for the user's request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.