Back to skill

Security audit

Gitee

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Gitee connector helper with read-only listed actions and no evidence of hidden, destructive, or unrelated behavior.

Before installing, understand that this skill can use your connected OOMOL/Gitee account to read visible Gitee account and repository information. Only connect accounts and scopes you are comfortable exposing to the OOMOL connector, and treat the first-time CLI install/auth steps as setup actions you should recognize and approve.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The manifest promises this skill is for 'searching and reading data', but the body explicitly discusses generic Gitee actions including potential [write] and [destructive] operations. This mismatch can cause downstream agents or users to trust the skill as read-only and invoke it in contexts where state-changing capabilities should have been excluded or separately authorized.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger text says to use this skill for ANY Gitee request, which is broader than necessary and may cause automatic invocation even when only a casual mention of Gitee appears. Over-broad routing increases the chance of unnecessary tool execution, schema inspection, or accidental progression toward authenticated connector actions in contexts that did not require this skill.

Static analysis

No suspicious patterns detected.