Back to skill

Security audit

Retell AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Retell AI connector that mainly lists and retrieves Retell AI data through OOMOL's oo CLI, with a notable caution around its CLI install command.

Install only if you intend to use OOMOL's oo CLI with your Retell AI workspace. Before running the one-line installer, review the installer source or use an official verified install path, and confirm any future Retell AI action that changes or deletes data before allowing the agent to run it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs piping a remote script directly into a shell (curl ... | bash), which executes unverified code from the network with no integrity check or review step. If the install endpoint, DNS, TLS chain, or hosting is compromised, users could run arbitrary attacker-controlled code on their system.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and top-level description present the skill as read/search-only, but the body explicitly supports arbitrary Retell AI actions, including write and destructive operations. This mismatch can mislead orchestrators or users into invoking a higher-privilege skill under a lower-risk label, undermining consent and policy controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger instruction says to use this skill for ANY Retell AI request, which is overly broad and can cause unintended invocation for tasks that may not need this connector or that require stricter controls. Broad routing language increases the chance of accidental execution against connected accounts and can amplify the impact of the skill's hidden write capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that write and destructive actions are supported even though the skill is framed elsewhere as only for searching and reading data. In agentic environments, this kind of capability understatement can bypass user expectations, routing logic, or approval policies that rely on the declared scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.