Back to skill

Security audit

Altoviz

Security checks for vulnerabilities and agentic risk

Overview

The skill’s normal Altoviz actions are scoped, but its setup instructions run remote installer scripts directly, which should be reviewed before use.

Before installing, review the oo CLI installation path carefully. Prefer a pinned, signed, or checksum-verified installer from OOMOL, and do not let an agent run the remote install commands automatically. Once the CLI is installed and connected, normal Altoviz reads are scoped, and writes should only proceed after confirming the exact customer data change.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve scripts from external URLs and immediately execute their contents through Bash or PowerShell. The scripts are not pinned to an immutable release, downloaded for inspection, checked against an expected cryptographic digest, or verified using a trusted signature.

Although HTTPS provides transport protection, it does not guarantee that the remote script remains unchanged after this Skill has been reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, TLS termination environment, or installer deployment pipeline could cause arbitrary attacker-controlled commands to be returned and executed.

This behavior is not necessary at the documented level of privilege. Installing the required CLI may be necessary, but executing a mutable network response directly is not. It also falls outside the Skill's declared allowed-tools: [Bash(oo *)] runtime restriction, which otherwise limits execution to the oo CLI.

The separately identified transmission of customer data through oo connector run is disclosed by the Skill and is intrinsic to its stated Altoviz connector functionality. The reviewed file does not show hidden recipients, raw-token collection, or unrelated data exfiltration.

Attack Path

  1. The oo CLI is absent, or an Agent encounters an error interpreted as oo: command not found.
  2. The Agent follows the first-time setup instructions in SKILL.md.
  3. The command requests the current installer from cli.oomol.com.
  4. An attacker who has compromised the download origin ...[truncated 1005 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation patterns.
  2. Pin the CLI to a specific, reviewed release rather than retrieving a mutable installer endpoint.
  3. Download the installation artifact to a local file without executing it automatically.
  4. Verify the artifact against a trusted, independently published SHA-256 digest or cryptographic signature before execution.
  5. Display the verified installer path and require explicit user approval before running it.
  6. Prefer an operating-system package manager or signed release package with version pinning and publisher verification.
  7. Keep installation outside normal Skill execution and preserve the declared Bash(oo *) least-privilege boundary.
  8. If automated installation is indispensable, restrict the source by exact version, enforce signature verification, fail closed on any verification error, and document the files and permissions modified by installation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs running a remote install script via curl ... | bash, which executes code fetched over the network without prior verification. If the hosting site, transport path, or script content is compromised, an attacker could achieve arbitrary code execution on the machine running the command.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase "Use this skill for ANY Altoviz request" is very broad and lacks clear scope boundaries or negative examples. While it is domain-limited to Altoviz, it still ambiguously covers any task merely involving Altoviz and could cause over-invocation instead of more specific routing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.