Back to skill

Security audit

TypeSafe AI

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a normal TypeSafe AI connector, but it under-describes external content evaluation and includes risky CLI installation guidance.

Review this before installing. It can use your OOMOL-connected TypeSafe AI account and may send text or JSON you provide to the external TypeSafe AI connector for evaluation. Avoid submitting secrets or sensitive documents unless you intend that sharing, and install the oo CLI through a verified method rather than blindly running the pipe-to-shell commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The safety section states that untagged actions are reads, yet evaluate is untagged even though it processes and sends supplied content to an external connector. This incorrect classification can cause agents to run evaluate without heightened checks, potentially exposing sensitive prompts, documents, or structured data under the false assumption that the action is harmless and read-only.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remotely fetched script without prior verification. If the distribution endpoint, transport, or hosting is compromised, this can lead to arbitrary code execution on the user's system.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and description constrain the skill to 'searching and reading data', but the documented evaluate action accepts arbitrary user text/JSON and performs analysis. This mismatch can mislead an agent or user into treating the skill as read-only, weakening scrutiny and enabling unintended data processing or transmission to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language says to use this skill for 'ANY TypeSafe AI request,' which is overly broad and may cause the agent to invoke it for tasks beyond the user's intent or beyond the safest available method. Overbroad routing increases the chance of unnecessary external data sharing and bypasses more context-appropriate controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.