Back to skill

Security audit

Web of Science Expanded

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only Web of Science connector wrapper with no hidden persistence or destructive behavior found.

Install only if you are comfortable using OOMOL as the intermediary for Web of Science searches and record retrieval. Before first use, verify the oo CLI installer source and expect your Web of Science queries, UIDs, and retrieved bibliographic data to pass through the OOMOL connector.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description uses blanket routing language ('Use this skill for ANY Web of Science Expanded request' and 'instead of calling the API directly'), which can cause the agent to invoke this skill for a very broad class of tasks without sufficient task-specific validation. Over-broad triggers increase the chance of unintended tool use, unnecessary exposure of user queries to an external connector, and bypass of more appropriate narrower workflows or consent checks.

Static analysis

No suspicious patterns detected.