Back to skill

Security audit

Bugsnag

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Bugsnag read-only connector, but its first-time setup tells agents to run unverified remote installer scripts directly in a shell.

Review this skill before installing. Its normal Bugsnag actions appear read-only and scoped through the oo CLI, but do not run the listed installer commands blindly; prefer a pinned or signed package, verify checksums or signatures where available, and approve setup steps only when you intend to connect your Bugsnag account through OOMOL.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Downloaded and Executed Through a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

The first-time setup instructions execute remotely hosted installation scripts directly through local command interpreters:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash
powershell
irm https://cli.oomol.com/install.ps1 | iex

Technical Analysis

Both installation commands retrieve mutable content from cli.oomol.com and immediately execute it with the privileges of the invoking user. The instructions do not pin an immutable release, validate a cryptographic checksum, verify a digital signature, or allow the script to be inspected before execution.

HTTPS protects the connection in transit but does not establish that the current script is safe or unchanged from the version reviewed during this audit. The effective code can change after the Skill has been published and audited. Compromise of the hosting service, publication pipeline, domain, DNS infrastructure, or TLS trust chain could consequently turn these installation commands into an arbitrary-code-execution channel.

Installing the oo CLI supports the declared Bugsnag connector functionality, but immediate execution of unverified remote content exceeds the minimum mechanism required. A pinned, signed, and independently verified package would provide the same capability with substantially lower supply-chain risk.

Attack Path

  1. The agent attempts to perform a Bugsnag operation using the oo CLI.
  2. The command fails because the CLI is not installed.
  3. The Skill directs the user or agent to run one of the remote installer commands.
  4. An attacker compromises or otherwise gains control over the mutable installation script or its delivery infrastructure.
  5. curl or PowerShell downloads the attacker-controlled payload.
  6. bash or Invoke-Expression executes the payload imm ...[truncated 1041 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation pipelines.
  2. Pin installation instructions to a specific reviewed CLI release and immutable artifact.
  3. Download the installer or package to disk without executing it automatically.
  4. Publish trusted SHA-256 or stronger checksums and require users to verify them before execution.
  5. Digitally sign release artifacts and verify signatures against a documented, trusted public key.
  6. Prefer signed packages distributed through established platform package managers.
  7. Require explicit user approval before installing software or executing an installer.
  8. Document the files, permissions, network access, and system changes required by the installer.
  9. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  10. If a script remains necessary, display or review the downloaded script before invoking a shell and fail closed when verification cannot be completed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remote script directly without prior verification, pinning, or integrity checking. If the distribution endpoint, TLS trust chain, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses very broad activation language: 'ANY Bugsnag request' and 'Whenever a task involves Bugsnag.' This lacks boundaries or exclusion conditions, so ordinary references to Bugsnag could trigger the skill even when the user did not intend connector-based access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.