Back to skill

Security audit

OSS Insight

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent OSS Insight connector, but its setup instructions include unverified remote install scripts and its documented write scope is broader and less clear than the listed actions.

Review the CLI setup before installing. Prefer a verified or package-manager installation path for oo, and confirm what the rank_* actions actually change before allowing them to run. Routine read/list OSS Insight queries appear consistent with the skill's purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs users to install software via 'curl ... | bash', which executes a remote script directly without prior verification or pinning. If the distribution endpoint, CDN, TLS trust chain, or upstream release process is compromised, this can lead to arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says the skill should be used for reading, creating, and updating data. However, the listed actions in the skill file are all framed as get/list/rank analytics operations, and the supposedly state-changing rank_* actions still read like query endpoints rather than creation or update operations. This creates a mismatch between the broad write-capable description and the documented functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY OSS Insight request," which is a very broad trigger and does not provide boundaries or negative examples for when the skill should not activate. This can overlap with many ordinary requests involving OSS Insight and may cause the skill to be invoked too aggressively.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The action descriptions for rank_collection_repos_by_issues, rank_collection_repos_by_pull_requests, and rank_collection_repos_by_stars describe ranking repositories in a collection, which ordinarily implies read-only analytics. Yet the surrounding safety documentation explicitly says [write] actions change OSS Insight state. That is an active contradiction between the documented intent and the apparent function semantics.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.