Back to skill

Security audit

BunnyCDN

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for BunnyCDN operations, but its setup instructions can run unverified internet installer scripts and its activation scope is broad.

Review the setup path before installing. Use this skill only when you intend to operate BunnyCDN through OOMOL, confirm any cache purge target, and avoid running the documented installer commands unless you independently trust and verify the OOMOL CLI installer.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 57
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction pipes a remotely downloaded, mutable shell script directly into bash. The script is executed without prior inspection, version pinning, checksum validation, or cryptographic signature verification. Consequently, the code executed by this command can differ from the content assessed during the Skill audit.

HTTPS authenticates the connection under normal conditions but does not guarantee that the hosted installer is safe or immutable. Compromise of the vendor's publishing account, web infrastructure, DNS, TLS termination, or installer build pipeline could turn this documented installation step into an arbitrary-code execution channel.

Installing the CLI can be relevant to the Skill's functionality, but immediate execution of an unverified remote script exceeds the minimum privileges and trust necessary to provide installation guidance.

Attack Path

  1. The oo command is unavailable, and execution fails with oo: command not found.
  2. The user or Agent follows the first-time setup instruction in SKILL.md.
  3. curl retrieves the current content of https://cli.oomol.com/install.sh.
  4. The response is passed directly to bash without being saved, reviewed, pinned, or integrity-checked.
  5. If the remote endpoint or its software supply chain has been compromised, attacker-controlled shell commands execute with the privileges of the user running the installation.
  6. The payload can access resources available to that user and may install additional components or persistence mechanisms.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. This may allow reading or modif ...[truncated 376 chars]

Remediation
View remediation

Remediation Suggestions

Remove the curl | bash pipeline. Direct users to a versioned release artifact from an official release page and pin a specific CLI version. Download the artifact to disk, verify a vendor-published cryptographic signature or SHA-256 checksum through an independently protected channel, and only then execute or install it.

Display the source, version, destination, and expected system changes before installation. Require explicit user approval for installation, avoid automatic fallback execution, and run the installer with ordinary user privileges unless a specific operation demonstrably requires elevation. Where available, prefer a trusted operating-system package manager with signed repository metadata.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows installation instruction retrieves a mutable PowerShell script with Invoke-RestMethod (irm) and immediately evaluates it using Invoke-Expression (iex). No exact version, expected digest, or trusted signature is checked before execution.

Invoke-Expression treats the remote response as executable PowerShell code. This gives the remote endpoint effective control over commands executed in the local PowerShell process and prevents meaningful review between download and execution. Although obtaining the CLI is relevant to first-time setup, executing mutable network content directly is not necessary and violates least-trust installation practices.

Attack Path

  1. The oo CLI is missing on a Windows environment.
  2. The user or Agent follows the PowerShell setup instruction.
  3. Invoke-RestMethod downloads the current response from https://cli.oomol.com/install.ps1.
  4. The pipeline sends the response directly to Invoke-Expression.
  5. A compromise of the hosting endpoint, publishing credentials, DNS, TLS infrastructure, or upstream release pipeline allows an attacker to substitute malicious PowerShell content.
  6. The substituted content executes in the current PowerShell session with the invoking user's permissions.

Impact Assessment

Exploitation permits arbitrary PowerShell execution with the current process's privileges. An attacker could access files and credentials available to the user, modify local tools or profiles, download additional payloads, establish persistence, or communicate with external systems. Execution from an elevated PowerShell session could permit system-wide changes. The audited instruction does not explicit ...[truncated 95 chars]

Remediation
View remediation

Remediation Suggestions

Remove the irm | iex instruction. Publish a versioned PowerShell installer or signed package that users download separately. Verify an Authenticode signature and a pinned cryptographic checksum before execution, then require explicit user confirmation.

Prefer a trusted Windows package manager or signed MSI/MSIX package where available. Document the publisher, exact version, expected digest, installation destination, and required permissions. Do not automatically execute installation commands after an authentication or connection failure, and avoid administrative execution unless it is strictly required and separately approved.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which is a classic supply-chain and remote code execution risk. If the install endpoint, CDN path, DNS, TLS trust, or upstream distribution is compromised, arbitrary code could run on the host with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY BunnyCDN request" and "Whenever a task involves BunnyCDN," which is an extremely broad activation condition. It does not provide scope boundaries or exclusion examples, so ordinary BunnyCDN-related discussion or indirect tasks could trigger the skill unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.