Back to skill

Security audit

SellerSprite

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for using SellerSprite through OOMOL, but its first-time setup includes unsafe remote installer commands that could execute changing code on the user's machine without integrity checks.

Review this skill before installing. Normal SellerSprite connector use appears purpose-aligned, but do not let an agent run the shown remote installer one-liners automatically. Prefer installing the oo CLI through a trusted, versioned package or official instructions with checksum/signature verification, then connect SellerSprite manually and approve any write action payloads before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses any integrity verification or review of the downloaded content, so if the hosting endpoint, network path, or distribution pipeline is compromised, arbitrary code would execute immediately on the local system. In a skill context, this is more dangerous because the content explicitly operationalizes the command as a remediation step and may normalize unsafe execution habits.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Static analysis

No suspicious patterns detected.