Back to skill

Security audit

Basin

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fits its Basin integration purpose, but its setup instructions tell users or agents to run an unverified internet installer directly in a shell.

Install only if you are comfortable with OOMOL's installer trust chain. Prefer reviewing the official install guide, downloading installers separately, and verifying publisher/version details before execution. For Basin data changes, require explicit confirmation for create, update, and delete actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:72
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72–76
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions retrieve mutable scripts from external URLs and immediately execute their contents using bash or PowerShell Invoke-Expression. There is no version pinning, cryptographic signature verification, checksum validation, or opportunity to inspect the downloaded files before execution.

HTTPS protects the connection in transit but does not guarantee that the remote script is safe or immutable. If the publisher infrastructure, hosting service, CDN, DNS resolution, TLS credentials, or release process is compromised, an attacker can replace the installer and obtain arbitrary code execution when an agent or user follows these instructions.

Installing the oo CLI can be relevant to the Skill's declared Basin integration. However, directly executing an unverified network response is not the minimum privilege or minimum trust mechanism necessary to install that dependency. The installation process also falls outside the restricted Bash(oo *) runtime scope declared by the Skill and invokes general-purpose shells capable of arbitrary system modification.

Attack Path

  1. The Skill attempts to perform a Basin operation, but the oo CLI is not installed.
  2. The agent or user follows the documented first-time setup procedure.
  3. An attacker compromises or gains control over the installer endpoint, its hosting infrastructure, DNS path, CDN, publisher account, or release pipeline.
  4. The attacker modifies the remote installer to include malicious shell or PowerShell commands.
  5. curl or irm downloads the attacker-controlled r ...[truncated 1243 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct download-to-shell patterns, including curl | bash and irm | iex.
  2. Prefer an official operating-system package manager or a signed installer distributed through a trusted package repository.
  3. Pin the CLI to a specific reviewed version rather than retrieving a mutable latest installer.
  4. If direct download is unavoidable, download the artifact to a local file without executing it automatically.
  5. Publish and verify a cryptographic signature from a documented publisher key. At minimum, verify a version-specific SHA-256 checksum obtained through an independently protected channel.
  6. Display the source, version, destination, and requested permissions to the user and obtain explicit approval before installation.
  7. Run installation with ordinary user privileges wherever possible; do not request administrator or root access unless a specific operation requires it.
  8. Keep dependency installation separate from normal Skill execution. On a missing CLI, return a clear error and direct the user to reviewed installation documentation rather than automatically executing setup commands.
  9. After installation, verify the executable path, ownership, permissions, version, and publisher signature before invoking it.
  10. Recommend avoiding installation on systems that contain sensitive credentials until the installer and distribution chain have been independently reviewed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk because any compromise of the hosting domain, TLS interception, or unexpected script change results in immediate arbitrary code execution on the user's machine without prior verification.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Static analysis

No suspicious patterns detected.