Back to skill

Security audit

API.Bible

Security checks for vulnerabilities and agentic risk

Overview

The skill’s API.Bible purpose is coherent, but its first-time setup tells agents to execute remote installer scripts directly, which is too much authority for a read-oriented connector skill.

Install only if you are comfortable with OOMOL’s CLI and account connection model. Do not let an agent run the documented remote installer commands automatically; prefer installing the oo CLI from reviewed, version-pinned, or verified official release steps, then use the skill for API.Bible read/search actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command downloads a mutable script from an external URL and immediately pipes it into Bash. It does not pin an immutable release, display the script for review, or verify a cryptographic checksum or signature before execution.

Although HTTPS protects the script while in transit, it does not ensure that the hosted payload remains identical to the version reviewed during this audit. Compromise of the hosting service, DNS infrastructure, deployment pipeline, or publisher account could cause arbitrary attacker-controlled commands to be returned and executed.

Installing the CLI may be a legitimate setup requirement, but executing an unverified remote script is not the minimum privilege or safest mechanism necessary to support API.Bible read operations.

Attack Path

  1. The oo command is unavailable, causing the user or agent to follow the first-time setup instructions.
  2. An attacker compromises the installer host, its release pipeline, or another component capable of changing the response from https://cli.oomol.com/install.sh.
  3. The user executes the documented command.
  4. curl retrieves the current remote response without validating its checksum, signature, or immutable version.
  5. Bash immediately executes the response with all permissions available to the invoking account.
  6. The malicious installer can access local data, alter files or tools, install persistence, or make additional network requests.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's privileges. The accessible scope may include user files, shell configuration, application credentials, API ...[truncated 335 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the pipe-to-shell installation command.

  • Direct users to a trusted package manager or an official, version-pinned release artifact.

  • If a script is unavoidable, separate download from execution so it can be inspected first.

  • Pin the installer to an immutable version rather than a mutable install.sh endpoint.

  • Publish a cryptographic checksum or signature through an independent trusted channel and require verification before execution.

  • Run installation with ordinary user privileges unless a narrowly defined operation explicitly requires elevation.

  • Document the installer's expected network connections, filesystem changes, and installed binaries.

  • Prefer an instruction such as:

    bash
    curl -fSLo oo-install.sh "https://trusted.example/releases/v1.2.3/install.sh"
    echo "<expected-sha256>  oo-install.sh" | sha256sum --check -
    less oo-install.sh
    bash oo-install.sh
    

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This command uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script from an external server and sends the response directly to Invoke-Expression (iex). The downloaded content is therefore interpreted as PowerShell code without version pinning, inspection, checksum validation, or signature verification.

The security of the execution depends entirely on the external endpoint and its supporting infrastructure at the moment the command runs. HTTPS does not prevent the publisher or a compromised hosting pipeline from replacing the reviewed installer with a different payload. Direct use of iex also removes the opportunity to inspect or scan a stable local artifact before execution.

The ability to install a required CLI may be legitimate, but immediate execution of mutable remote content grants broader capability than is necessary for the Skill's declared read-only API.Bible functionality.

Attack Path

  1. The oo command is unavailable on a Windows system, prompting use of the documented setup command.
  2. An attacker gains control over the installer endpoint, publisher account, or release infrastructure.
  3. The attacker replaces the response from https://cli.oomol.com/install.ps1 with malicious PowerShell.
  4. The user executes the documented command.
  5. irm retrieves the attacker-controlled response.
  6. iex immediately evaluates that response in the current PowerShell process.
  7. The payload performs arbitrary actions with the invoking user's effective permissions.

Impact Assessment

Exploitation permits arbitrary PowerShell execution with the privileges of the current user. A payload could read ...[truncated 412 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex pattern.

  • Distribute a version-pinned, signed installer or package through a trusted Windows package manager.

  • Download the installer to a local file before execution and require signature or checksum validation.

  • Use Authenticode signing and verify that the signature is valid and belongs to the expected publisher.

  • Pin documentation to an immutable release URL rather than a mutable install.ps1 endpoint.

  • Avoid administrative execution unless a documented, narrowly scoped installation step requires it.

  • Document all expected filesystem, registry, process, and network effects.

  • Prefer a workflow such as:

    powershell
    Invoke-WebRequest "https://trusted.example/releases/v1.2.3/install.ps1" -OutFile ".\install.ps1"
    if ((Get-FileHash ".\install.ps1" -Algorithm SHA256).Hash -ne "<EXPECTED_SHA256>") {
        throw "Installer integrity verification failed"
    }
    Get-Content ".\install.ps1"
    & ".\install.ps1"
    
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote-code-execution risk because any compromise of the hosting domain, transport, installer content, or update process would execute arbitrary code on the user's machine without review. In this skill's context, the danger is increased because the instruction is presented as an operational fallback step the agent may run automatically when the CLI is missing.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Static analysis

No suspicious patterns detected.