Back to skill

Security audit

Slite

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly for Slite automation, but its setup guidance asks users to run a remote installer directly in a shell and it routes Slite content through an additional service.

Review the oo CLI installation method before installing, prefer a verified or package-manager installation path if available, and connect Slite with the minimum permissions needed. Be aware that Slite request payloads and responses are processed through OOMOL, and confirm all write or delete actions carefully.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installation Scripts Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions retrieve mutable content from remote OOMOL endpoints and immediately pass it to a command interpreter. Neither command pins the downloaded script to an immutable release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the payload before execution.

TLS protects the connection in transit but does not protect users if the hosting service, DNS resolution, publishing account, build pipeline, or remote installation script is compromised. Because the effective executable payload is controlled remotely, it may change after this Skill has been reviewed.

Installing the required CLI supports the declared functionality, but immediate curl | bash or irm | iex execution is not the minimum-risk installation method. The same functionality can be provided through signed packages or separately downloaded and verified artifacts.

Attack Path

  1. The oo CLI is absent, and an attempted connector operation fails with oo: command not found.
  2. The user or agent follows the documented first-time setup instructions.
  3. An attacker compromises the installation endpoint, its publishing pipeline, or another component capable of changing the returned script.
  4. curl or irm retrieves the attacker-controlled response.
  5. The pipe sends the response directly to Bash or PowerShell without integrity validation or review.
  6. The malicious script ...[truncated 700 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace direct download-to-shell execution with installation through a trusted operating-system package manager or a signed release package.
  • Pin the CLI to a specific immutable version rather than a mutable installation endpoint.
  • Publish cryptographic checksums and signed provenance for every supported artifact.
  • Download the artifact to a local file, verify its signature and checksum, and only then execute it.
  • Require explicit user approval before installation and clearly describe the commands and privileges involved.
  • Avoid running the installer with administrator or root privileges unless a documented component strictly requires them.
  • If bootstrap scripts must remain available, publish their source in a version-controlled repository and reference a commit-pinned version.

other

Warning
Location
SKILL.md:3
Finding

Sensitive Slite Content Routed Through an Additional Third-Party Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3, 14, and 25–31
Vulnerability Type: Third-party sensitive-data exposure
Risk Level: Medium

Vulnerable Code

yaml
description: "Slite (slite.com). Use this skill for ANY Slite request — reading, creating, updating, and deleting data. Whenever a task involves Slite, use this skill instead of calling the API directly."
markdown
Operate **Slite** through your OOMOL-connected account. This skill calls the `slite` connector with the [oo CLI](https://github.com/oomol-lab/oo-cli); OOMOL injects credentials server-side, so you never handle raw tokens.
bash
oo connector schema "slite" --action "<action_name>"
bash
oo connector run "slite" --action "<action_name>" --data '<json>' --json

Technical Analysis

The Skill categorically directs all Slite operations through OOMOL's CLI and connector service rather than permitting direct communication with Slite. Payloads supplied through --data can contain note titles, note bodies, search terms, identifiers, collection attributes, or other workspace information. Responses may contain equally sensitive Slite content.

OOMOL's intermediary role is disclosed, and the audited file does not demonstrate covert exfiltration or misuse of the data. Nevertheless, this architecture adds another service provider and trust boundary to every Slite request. It can expose sensitive workspace content and metadata to infrastructure beyond Slite itself.

The broad instruction to use this connector for “ANY Slite request” does not provide data minimization guidance or distinguish low-sensitivity metadata from confidential note content. The file also does not specify intermediary retention, logging, regional processing, encryption controls, or whether payloads are used for any secondary purpose.

Attack Path

  1. A user asks the agent to read, search, create, or update Slite ...[truncated 1268 chars]
Remediation
View remediation

Remediation Suggestions

  • Clearly disclose before use that request payloads and Slite responses are processed by OOMOL infrastructure.
  • Obtain informed user approval before transmitting confidential note content through the intermediary.
  • Document what data is transmitted, logged, retained, encrypted, and accessible to the connector provider.
  • Minimize each payload to fields strictly necessary for the requested action.
  • Avoid including unrelated secrets, credentials, or unnecessary document content in --data.
  • Permit direct Slite API access when third-party processing is not required.
  • Scope the connected Slite credentials to the minimum permissions necessary for intended actions.
  • Separate read-only and write-capable connections where supported, and require explicit confirmation before write or destructive operations.
  • Provide incident-response and credential-revocation guidance for compromise of the connector account or infrastructure.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs fetching and piping a remote script directly into a shell, which creates a classic supply-chain and remote code execution risk. If the install endpoint, transport path, or hosting account is compromised, an operator following the instructions could execute arbitrary code on their machine with no integrity verification.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use this skill for "ANY Slite request" and "Whenever a task involves Slite," which is extremely broad and overlaps with many ordinary requests that merely mention Slite. It does not define narrower activation conditions, exclusions, or examples of when the skill should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.