Back to skill

Security audit

ByteForms

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent ByteForms read-only connector, but its fallback setup tells users to run unverified internet installer scripts directly.

Review the installer path before using this skill. Prefer installing the oo CLI through an official signed or package-manager method, or manually download and verify the installer before running it. Once installed, use the skill only with ByteForms data you are comfortable exposing through your connected OOMOL account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 57
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction streams a mutable script from an external server directly into Bash. The downloaded content is neither version-pinned nor verified using a cryptographic signature or trusted digest, and users cannot inspect it before execution.

HTTPS protects the connection in transit but does not ensure that the server, hosting account, release process, or delivered script remains trustworthy. Because the effective payload can change after the Skill has been reviewed, compromise of the distribution endpoint could turn this installation step into arbitrary remote code execution.

Installing the CLI may be necessary when oo is unavailable, but immediate pipe-to-shell execution exceeds the minimum privilege and trust required. A verified package or a download-review-verify-install workflow can provide the same functionality with substantially lower risk.

Attack Path

  1. The oo command is unavailable, causing the user or agent to follow the documented fallback.
  2. An attacker compromises the installer endpoint, its hosting infrastructure, DNS resolution, or the publisher’s deployment process.
  3. The attacker replaces or alters install.sh with malicious shell commands.
  4. curl retrieves the attacker-controlled response and passes it directly to Bash.
  5. Bash executes the payload without integrity verification or prior inspection.
  6. The payload performs arbitrary actions with the privileges of the account running the command.

Impact Assessment

Successful exploitation grants arbitrary command execution under the invoking user’s privileges. Depending on that account’s permissions, the payload could read or modify user fi ...[truncated 342 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation instruction.
  • Prefer an official operating-system package manager or a signed, version-pinned release artifact.
  • If a standalone installer is required, download it to a local file rather than executing the network stream.
  • Verify the file against a publisher signature and a SHA-256 digest obtained through a trusted, independently authenticated channel.
  • Display or review the verified script before execution.
  • Require explicit user approval before running an installer.
  • Run installation with ordinary user privileges unless a narrowly defined operation demonstrably requires elevation.
  • Pin the installer or CLI version so that the audited instructions resolve to a reproducible artifact.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This instruction downloads a mutable PowerShell script with Invoke-RestMethod (irm) and immediately evaluates the response using Invoke-Expression (iex). It provides no version pinning, signature validation, digest verification, or opportunity to inspect the payload before execution.

Invoke-Expression treats the server response as executable PowerShell code. Consequently, compromise of the remote endpoint or its release pipeline directly creates a code-execution path on the user’s Windows system. TLS alone does not establish the integrity or immutability of the script beyond transport.

While installing the required CLI is a legitimate setup objective, executing unverified network content is not necessary to accomplish it and violates least-trust installation practices.

Attack Path

  1. The oo command is missing on a Windows system.
  2. The user or agent follows the documented first-time setup command.
  3. An attacker compromises the installer endpoint, publisher account, hosting infrastructure, DNS resolution, or deployment pipeline.
  4. Invoke-RestMethod retrieves the attacker-controlled PowerShell response.
  5. The pipeline sends the response directly to Invoke-Expression.
  6. PowerShell executes the malicious content with the privileges and accessible resources of the invoking process.

Impact Assessment

Exploitation permits arbitrary PowerShell execution as the invoking user. The payload could access user-readable files and credentials, modify the user profile, tamper with developer tooling, download further malware, or create user-level persistence. If run from an elevated PowerShell session, it could obtain ...[truncated 164 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Distribute the CLI through a trusted Windows package manager or a signed, version-pinned installer.
  • Download any PowerShell installer to disk without evaluating it immediately.
  • Validate an Authenticode signature and a pinned cryptographic digest before execution.
  • Allow the user to inspect the verified script and require explicit approval before running it.
  • Execute from a non-administrative PowerShell session unless a specific installation operation requires elevation.
  • Document the expected publisher identity, artifact version, digest, and verification procedure.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill recommends installing the CLI via curl ... | bash, which executes a remotely fetched script without verification. In a skill context, this is especially dangerous because users may treat setup instructions as trusted and run arbitrary code from the network, enabling supply-chain compromise or malicious script execution if the host, transport, or distribution channel is compromised.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and description frame the skill as being for 'searching and reading data', but the body instructs use of arbitrary connector actions and even defines safety handling for hypothetical [write] and [destructive] actions. That mismatch can mislead users, policy engines, or reviewers into granting broader trust than warranted, increasing the chance that state-changing operations are invoked under a read-only expectation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.