Back to skill

Security audit

Vapi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Vapi connector skill with clear write/delete warnings, though its optional CLI setup uses a risky pipe-to-shell installer pattern.

Install only if you are comfortable using OOMOL as the connector for your Vapi account. Before using the setup commands, prefer the official install guide or verify the installer source yourself; review payloads carefully before approving write or destructive Vapi actions.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Content
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
Confidence
98% confidence
Finding
The skill instructs users to install software via a remote script piped directly into a shell (`curl ... | bash`), which executes network-fetched code without prior verification. If the install endpoint, transport path, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Static analysis

No suspicious patterns detected.