Back to skill

Security audit

Plate Recognizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for using Plate Recognizer through OOMOL, but its first-time setup tells agents to run unverified remote installer scripts and its routing instructions are overly broad.

Review this skill before installing. It appears intended to operate Plate Recognizer through OOMOL, but do not run the listed installer commands unless you trust the OOMOL CLI distribution path and have independently checked the installer source or a signed package. Be aware that plate images and recognition data may pass through OOMOL as well as Plate Recognizer.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:52
Finding

Unverified Remote Shell Script Execution

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ``` ### Technical Analysis The installation command downloads a mutable shell script from an external URL and immediately pipes it into Bash. The Skill does not pin the script to a version or cryptographic digest, verify a digital signature, or provide an opportunity to inspect the downloaded content before execution. HTTPS protects the connection in transit but does not ensure that the hosted script remains identical to the version available when the Skill was audited. Compromise of the OOMOL domain, hosting infrastructure, release process, or administrative credentials could therefore replace the installer with arbitrary commands. Installing a required CLI can be consistent with the Skill's function, but immediate execution of unverified remote content is not the minimum privilege or safest installation mechanism necessary to achieve that purpose. ### Attack Path 1. The `oo` command is unavailable on the user's system. 2. The setup instructions direct the user or agent to run the documented installation command. 3. `curl` retrieves the current contents of `https://cli.oomol.com/install.sh`. 4. The response is sent directly to Bash without integrity or authenticity verification. 5. A compromised or malicious response executes arbitrary shell commands with the privileges of the invoking account. ### Impact Assessment Successful exploitation permits arbitrary code execution under the invoking user's privileges. Potential effects include reading or modifying files accessible to that account, stealing locally available credentials, installing additional software, alte ...[truncated 317 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote PowerShell Script Execution

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:3
Finding

Forced Routing of Plate Recognition Data Through an Intermediary

Content
View full analysis
" --data '' --json ``` ### Technical Analysis The Skill contains a universal tool-selection instruction requiring every Plate Recognizer request to use this Skill rather than calling the service directly. Requests are sent through the `oo` CLI and OOMOL connector, introducing OOMOL as an intermediary. Network transmission is necessary for the declared cloud-based plate-recognition functionality, and the Skill openly states that it uses OOMOL. The reviewed content does not demonstrate covert credential theft: credentials are described as being injected server-side. Nevertheless, the universal routing mandate can override a more privacy-preserving direct API path and may cause vehicle images, license-plate information, and associated request metadata to pass through an additional service provider. The instruction therefore exceeds the minimum routing constraint necessary to describe how the Skill works. It should not unconditionally displace direct access without informed user choice. ### Attack Path 1. A user requests recognition of a number plate from an image. 2. The Skill's broad instruction causes the agent to select the OOMOL connector instead of a direct Plate Recognizer API integration. 3. The image or schema-def ...[truncated 968 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI via a remote shell pipeline (curl ... | bash), which executes code fetched over the network without prior verification. If the distribution endpoint, transport, DNS, or hosting were compromised, this could lead to arbitrary code execution on the user's machine during setup.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Plate Recognizer request" and "Whenever a task involves Plate Recognizer," which is an extremely broad activation condition for a markdown skill description. It does not define boundaries, exclusions, or negative examples, so ordinary references to Plate Recognizer could unintentionally trigger the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.