Back to skill

Security audit

ASIN Data API

Security checks for vulnerabilities and agentic risk

Overview

This ASIN Data API connector is mostly coherent, but its setup instructions tell the agent or user to run an unverified remote installer directly in a shell.

Before installing, use verified OOMOL CLI installation documentation or a signed/package-manager release instead of piping a remote script directly into a shell. Only connect the ASIN Data API account you intend to use, and require explicit confirmation before any update or delete action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions pipe remotely downloaded content directly into Bash or PowerShell. The downloaded installer is mutable and is executed without version pinning, cryptographic signature verification, checksum validation, or an opportunity for local review.

Although the download domain is associated with the declared OOMOL CLI, this pattern makes the effective code executed by the Skill dependent on whatever the remote endpoint serves at invocation time. Consequently, the installer can change after the Skill has been audited. Compromise of the hosting infrastructure, publishing account, DNS resolution, TLS termination, or installer distribution process could cause arbitrary attacker-controlled commands to execute.

Installing the required CLI is relevant to the Skill's functionality, but immediate execution of an unverified remote response exceeds the minimum necessary installation behavior. A safer workflow can download a fixed release, authenticate it, and execute it only after verification.

Attack Path

  1. The oo command is unavailable and an agent or user follows the first-time setup instructions.
  2. An attacker compromises or otherwise gains control over the installer delivery path or remote installer content.
  3. The attacker modifies install.sh or install.ps1 to include malicious commands.
  4. curl | bash or irm | iex passes the response directly to a command interpreter.
  5. The malicious commands execute without integrity validation or prior inspection.
  6. The payload accesses resources available to the invoking ...[truncated 871 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex installation commands.
  2. Pin installation instructions to a specific, immutable CLI version rather than a mutable installer URL.
  3. Download the release artifact to a local file without executing it immediately.
  4. Publish the expected SHA-256 digest through an independently protected release channel and verify it before execution.
  5. Prefer signed release artifacts and verify the publisher signature against a documented, pinned public key.
  6. Use a trusted platform package manager where packages are versioned and authenticated.
  7. Allow the user to inspect and explicitly approve the downloaded artifact before execution.
  8. Run installation with ordinary user privileges and avoid requesting administrative access unless a specific installation step requires it.
  9. Document the files, directories, network endpoints, and configuration changes made by the installer.
  10. Fail closed if integrity or signature verification cannot be completed.

A safer installation sequence should follow this model:

bash
curl -fL -o oo-installer.sh "https://trusted.example/releases/vX.Y.Z/install.sh"
echo "EXPECTED_SHA256  oo-installer.sh" | sha256sum --check -
less oo-installer.sh
bash oo-installer.sh

The release URL and digest must be replaced with authentic, version-specific values published through a protected release process.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the hosting server, transport, or script contents are compromised, arbitrary code would run immediately in the user's environment.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY ASIN Data API request" and "Whenever a task involves ASIN Data API, use this skill," which is a very broad activation condition. It does not provide narrower trigger examples or exclusion conditions, so the invocation scope may be broader than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.