Back to skill

Security audit

MailerLite

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing MailerLite through OOMOL, but its first-time setup tells agents to run unverified remote installer scripts and it can handle sensitive subscriber data.

Review the OOMOL CLI installation path before installing, and avoid running the provided remote installer commands automatically. Only connect MailerLite if you are comfortable routing subscriber and account operation data through OOMOL, and require explicit confirmation before any write or delete action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:67
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis
Remediation
View remediation
oo-installer.sh' | sha256sum --check - ``` 6. Prefer signed artifacts and verify the publisher's signature using a pinned, documented public key. 7. Allow the user or administrator to inspect the downloaded file before explicitly executing it. 8. Recommend execution as an unprivileged user and document all files, permissions, and system changes made by the installer. 9. Where possible, use trusted operating-system package managers with package signing and reproducible version selection. ]]>

other

Warning
Location
SKILL.md:28
Finding

Potentially Sensitive MailerLite Data Routed Through a Third-Party Connector

Content
View full analysis
" ``` ```bash oo connector run "mailerlite" --action "" --data '' --json ``` ### Technical Analysis The Skill requires MailerLite requests to pass through the OOMOL connector rather than allowing direct use of MailerLite's official API. As a result, action payloads and returned records are processed by an additional third party. The intermediary is disclosed and is part of the Skill's declared architecture, so the reviewed file does not demonstrate covert exfiltration. Nevertheless, MailerLite subscriber operations can involve email addresses, custom subscriber fields, identifiers, group membership, and mutation payloads. Routing this information through another service introduces an additional trust boundary, processor, network endpoint, and potential retention location. This architecture exceeds the minimum network path technically required to communicate with MailerLite because a direct MailerLite API integration would not need the additional intermediary. The file does not document data minimization, connector retention, logging behavior, regional processing, or privacy controls. ### Attack Path 1. A user asks the agent to read or modify MailerLite data. 2. The agent constructs a JSON payload for `oo connector run`. 3. The `oo` CLI sends the actio ...[truncated 1260 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install missing tooling by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the endpoint, transport, or published install script is compromised, the agent may execute arbitrary attacker-controlled code on the host.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L03 says to use this skill for "ANY MailerLite request" and "Whenever a task involves MailerLite," which is a very broad activation condition without boundaries or exclusion examples. This can cause unintended invocation for loosely related discussions or tasks that merely mention MailerLite.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.