Back to skill

Security audit

Brandfetch

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent read-only Brandfetch connector, but its setup instructions include executing a remote installer directly in a shell without verification.

Review the oo CLI installation path before installing. Prefer official, version-pinned packages or installer downloads that can be inspected and verified, and avoid running the provided one-line remote shell commands unless you trust OOMOL's installer infrastructure and understand it will execute local code.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions pipe scripts downloaded from cli.oomol.com directly into local command interpreters. The Unix command passes the HTTP response to Bash, while the Windows command invokes the downloaded PowerShell content through Invoke-Expression.

Neither instruction pins a specific installer version nor verifies a cryptographic signature or trusted checksum before execution. HTTPS protects the connection in transit, but it does not ensure that the server, publishing account, or hosted script remains uncompromised. The effective executable payload can also change after the Skill has been reviewed.

Installing the required CLI may be legitimate for the declared Brandfetch functionality, but executing an uninspected, mutable remote response is not the minimum privilege or minimum-risk approach necessary to perform that installation.

Attack Path

  1. A user attempts to use the Skill on a system where the oo CLI is unavailable.
  2. The documented first-time setup directs the user to execute one of the remote installation commands.
  3. An attacker compromises the installer host, publishing process, DNS or delivery infrastructure, or otherwise causes the URL to return modified script content.
  4. The shell executes the returned content immediately, without checksum validation, signature verification, version pinning, or a manual review step.
  5. The malicious installer performs arbitrary actions under the privileges of the user who ran the command and may retrieve additional payloads.

Impact Assessment

Successful exploit ...[truncated 581 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove direct curl | bash and irm | iex installation instructions.
  2. Link to a version-pinned release artifact from an authenticated release channel.
  3. Require users to download the installer to disk before execution.
  4. Publish an expected SHA-256 or stronger digest over a separately authenticated channel and require verification before execution.
  5. Prefer a cryptographically signed package and document signature verification using a pinned, trusted signing identity.
  6. Allow users to inspect the downloaded script before running it.
  7. Document the installer's expected network access, filesystem modifications, and required privileges.
  8. Avoid requesting administrative privileges unless a specific installation operation requires them.
  9. Prefer established platform package managers with signed repositories and pinned package versions where available.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses integrity verification, gives the remote server immediate code execution, and is especially risky in a skill because an automated agent may follow the instruction without independent review.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Static analysis

No suspicious patterns detected.