Back to skill

Security audit

APIVerve

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its APIVerve connector purpose, but its fallback setup tells users or agents to run unverified remote installer scripts directly in a shell.

Install the oo CLI only if you trust OOMOL's installer source, and prefer a documented package manager or a downloaded installer with checksum or signature verification. Normal APIVerve actions appear narrowly scoped to the oo connector, but review setup commands carefully before running them.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote Installer Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63-67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions download mutable content from cli.oomol.com and immediately pass it to a command interpreter. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded file before execution.

HTTPS provides transport protection but does not establish that the script itself is safe. Compromise of the hosting infrastructure, domain, CDN, publishing credentials, or installer-generation process could replace the script after the Skill has been reviewed. The effective code executed by these instructions can therefore change independently of this package.

Although installation is presented as a fallback for a missing CLI and the domain is associated with the declared service provider, direct remote-script execution is not required to perform the Skill's normal APIVerve operations. It exceeds the minimum privilege needed by an already-installed client and creates a supply-chain code-execution channel.

Attack Path

  1. A user or Agent attempts an APIVerve action and receives an oo: command not found error.
  2. The fallback instructions cause the macOS/Linux command or Windows PowerShell command to be executed.
  3. The current response from cli.oomol.com is downloaded without version pinning or integrity verification.
  4. bash or PowerShell immediately interprets the response as executable code.
  5. If the remote script or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the invoking process.
  6. Those commands ...[truncated 969 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation commands from the Skill instructions.
  2. Direct users to a documented package manager or a versioned release page instead of executing a mutable URL.
  3. Pin the CLI to an explicitly reviewed version.
  4. Publish SHA-256 checksums and cryptographic signatures through an independently protected channel.
  5. Require users to download the installer to a local file, verify its signature or checksum, and inspect it before execution.
  6. Keep CLI installation as an explicit, user-controlled prerequisite rather than allowing an Agent to perform it automatically after a command failure.
  7. Run installation with ordinary user privileges whenever possible and document any permissions genuinely required.
  8. If automated installation is unavoidable, use a signed package repository with version pinning and fail closed when integrity verification cannot be completed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses integrity verification and review of the downloaded content, so if the install endpoint, transport, hosting, or upstream release pipeline is compromised, arbitrary code executes immediately on the host.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Static analysis

No suspicious patterns detected.