Back to skill

Security audit

Docparser

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Docparser automation, but its first-time setup tells the agent to execute a remotely fetched installer script without verification.

Review this skill before installing if the oo CLI is not already installed. Normal Docparser use is scoped and asks for confirmation before writes, but the setup command can execute code from OOMOL's installer host on your machine; prefer installing the CLI through a verified package or checksum/signature-checked release path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs the agent to install the CLI by piping a remotely fetched script directly into bash, which is a classic supply-chain and arbitrary code execution risk. If the install host, network path, or script content is compromised, this would execute attacker-controlled code on the local system without prior verification.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Static analysis

No suspicious patterns detected.