Back to skill

Security audit

You.com

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent You.com connector, but its setup instructions include direct remote script execution that deserves review before installation.

Install only if you trust OOMOL and are comfortable reviewing or manually running the CLI installer yourself. Do not allow the remote install commands to run automatically, and confirm any research or finance actions that may use account credits or change provider-side state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software using a remote script piped directly into a shell (curl ... | bash), which is a classic unsafe pattern because it executes unreviewed code fetched at runtime. Even though framed as first-time setup, embedding this command in a skill increases the likelihood that an agent may suggest or run it automatically after an error, creating a supply-chain and arbitrary code execution risk.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s trigger text says to use it for "ANY You.com request," which is overly broad and can cause the agent to route a wide range of loosely related tasks through this skill without clear scope limits. In a security-sensitive environment, broad activation language increases the chance of unintended tool use, including invoking connector-backed actions when a simpler or safer path would suffice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.