Back to skill

Security audit

Web of Science

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Web of Science connector helper focused on searching and reading data through OOMOL, with no artifact evidence of hidden or destructive behavior.

Install only if you intend to use OOMOL with a connected Web of Science account. Review the live action schema before use, and do not run the optional CLI install or account connection steps unless you trust OOMOL and need that setup.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction to use this skill for "ANY Web of Science request" creates an unnecessarily broad routing rule with weak scope boundaries. In an agent system, such blanket phrasing can cause over-selection of this skill for tasks that only partially relate to Web of Science, increasing the chance of unintended command execution, misuse of connected credentials, or bypass of safer task-specific handling.

Static analysis

No suspicious patterns detected.