Back to skill

Security audit

AMap

Security checks for vulnerabilities and agentic risk

Overview

This AMap skill is mostly coherent, but its setup instructions tell users or agents to run unverified remote installer scripts directly.

Review the setup path before installing. Prefer installing the oo CLI from a verified, versioned source with signature or checksum validation, and do not let an agent run the curl-to-bash or irm-to-iex commands automatically. Once the CLI is already installed and connected, the skill's AMap connector usage appears read-only and purpose-aligned.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:69
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command pipes a mutable network response directly into bash. The downloaded script is neither version-pinned nor verified using a cryptographic signature or checksum, and the command provides no opportunity to inspect the payload before execution.

HTTPS protects the connection in transit but does not establish that the current script matches the version reviewed with this Skill. If the hosting service, publishing account, DNS resolution, certificate trust chain, or deployment pipeline is compromised, the URL can return attacker-controlled shell commands.

The installer is only needed when the oo CLI is unavailable, but unrestricted remote shell execution exceeds the minimum privilege needed to document or install a known CLI artifact. The Skill should instead use a fixed, independently verifiable release.

Attack Path

  1. An attacker compromises the installer host, its deployment pipeline, publishing account, or another component capable of changing the response from https://cli.oomol.com/install.sh.
  2. The attacker replaces the installer response with malicious shell commands.
  3. The oo CLI is absent, causing the documented first-time setup path to be used.
  4. A user or agent runs the documented curl | bash command.
  5. bash executes the attacker-controlled response immediately with the privileges of the invoking account.
  6. The payload can access resources available to that account and may attempt further compromise or persistence.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's privileges. The payload could read or modify user-accessible files, access credentials available to ...[truncated 211 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation instruction.
  • Refer users to a version-pinned release hosted in the project's verified official repository.
  • Download the installer or binary to a local file without executing it automatically.
  • Publish and require verification of a cryptographic signature or checksum obtained through an independently protected channel.
  • Allow inspection of the downloaded script before execution.
  • Prefer a signed operating-system package or trusted package-manager distribution.
  • Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  • Document the exact files, permissions, and system changes performed by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:73
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 73
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This command retrieves a mutable PowerShell script using Invoke-RestMethod (irm) and passes the response directly to Invoke-Expression (iex). Invoke-Expression interprets the downloaded text as PowerShell code without version pinning, signature validation, checksum verification, or prior inspection.

The content served by the URL can change after the Skill has been audited. A compromise of the hosting infrastructure, publishing credentials, DNS or certificate trust, or release pipeline could therefore turn this setup instruction into an arbitrary code-execution channel.

Although installing the CLI supports the Skill's operation, executing an unverified response with all privileges available to the PowerShell process is not the least-privilege installation method.

Attack Path

  1. An attacker gains the ability to alter the response from https://cli.oomol.com/install.ps1.
  2. The response is replaced with attacker-controlled PowerShell commands.
  3. A user encounters the missing-CLI setup condition and follows the documented PowerShell instruction.
  4. irm downloads the malicious response.
  5. iex executes that response immediately in the current PowerShell session.
  6. The payload operates with the invoking user's permissions and can attempt credential access, file modification, additional downloads, or persistence.

Impact Assessment

Exploitation results in arbitrary PowerShell execution with the privileges of the invoking user. This may expose user-accessible files and credentials, permit modification of account configuration, and allow installation of additional payloads or persistence mechanisms. Execution from an elevated PowerShell sessi ...[truncated 40 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Distribute a version-pinned and Authenticode-signed PowerShell installer or signed binary.
  • Download the artifact separately and validate its publisher signature and a published cryptographic checksum before execution.
  • Use a trusted Windows package manager with publisher and package-integrity verification where possible.
  • Provide a manual inspection step and display the exact artifact version being installed.
  • Avoid requesting administrator privileges unless a documented installation step strictly requires them.
  • Publish the installer's expected filesystem, registry, service, and network changes.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs users to install software via curl ... | bash, which downloads and immediately executes a remote script without verification. If the remote host, transport, or served script is compromised, this becomes arbitrary code execution on the user's machine; because this is a setup path inside the skill, an agent may surface or run it during troubleshooting.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says to use this skill for ANY AMap request and instead of calling the API directly, which is an overly broad routing instruction. This can cause an agent to invoke the skill in situations where a narrower or safer path would be more appropriate, increasing the blast radius of any unsafe behavior or bad setup steps embedded in the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.