Back to skill

Security audit

BoloForms

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent BoloForms connector, but it includes first-time setup instructions that run an unverified internet installer script.

Before installing, review the oo CLI installation path carefully. Prefer official, versioned installation instructions with verification instead of running a remote script directly, and confirm the exact recipients and payload before using the signing action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Scripts Executed Directly by Shells

Content
View full analysis
Remediation
View remediation
/install.sh" ``` 5. Publish and verify a pinned SHA-256 checksum before execution: ```bash echo " oo-installer.sh" | sha256sum --check - ``` 6. Prefer publisher-backed cryptographic signature verification over checksums alone, with the trusted public key distributed through an independent channel. 7. Allow the user to inspect the downloaded artifact before running it. 8. Request explicit user approval immediately before executing any installer. 9. Run installation with the lowest practical privileges; do not request administrator or root access unless a specific installation target requires it. 10. Apply equivalent version pinning, signature validation, separate download, and explicit approval controls to the PowerShell installer. 11. Document the artifact source, expected publisher identity, version, checksum, installation destinations, and permissions required. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a curl ... | bash installation command that downloads and immediately executes a remote script. Even though it is presented as first-time setup, this pattern creates a supply-chain and remote-code-execution risk if the server, transport, or published script is compromised, and the skill context makes it more dangerous because users may trust and run it during troubleshooting.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says to use this skill for ANY BoloForms request and instead of calling the API directly, which is an overly broad routing instruction. This can cause the agent to invoke the skill in situations where BoloForms is only mentioned tangentially or where a narrower, safer tool would be more appropriate, increasing the chance of unintended data access or state-changing operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.