Back to skill

Security audit

Intercom

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly for Intercom, but its setup instructions include running remote installer scripts directly in a shell.

Install this only if you trust OOMOL and are comfortable connecting it to your Intercom workspace. Before running the installer commands, prefer an official package-manager or verified installer path, and review any remote script locally. Treat write and destructive Intercom actions as business-impacting operations and require explicit approval for the exact payload and target.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses integrity verification and gives the remote server or any attacker able to tamper with that response immediate code execution on the user's machine. In a skill context, this is especially risky because it is presented as an operational remediation step for auth/setup failures, increasing the chance an agent or user will run it without scrutiny.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

Static analysis

No suspicious patterns detected.