Back to skill

Security audit

Capsule CRM

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Capsule CRM connector, but its setup instructions tell users to run a downloaded installer script directly and it can change or delete CRM records.

Install only if you trust OOMOL and are comfortable granting the connector access to Capsule CRM. Do not run the installer pipe commands blindly; use a verified package or inspect and verify the installer first, and require explicit confirmation before any create, update, or delete action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:79
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 79–83
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions pipe network responses directly into Bash or PowerShell. Neither command pins an installer version, verifies a cryptographic checksum or signature, nor gives the user an opportunity to inspect the downloaded code before execution.

Although cli.oomol.com is consistent with the Skill's declared OOMOL integration, the effective payload is mutable and exists outside the audited project. Consequently, its behavior can change after the Skill has been reviewed. Compromise of the hosting service, deployment pipeline, DNS resolution, TLS endpoint, or OOMOL distribution infrastructure could cause arbitrary attacker-controlled commands to be executed.

Installing the oo CLI is relevant only when the required CLI is missing, but immediate execution of an unverified remote response exceeds the minimum safe mechanism necessary to perform that installation.

Attack Path

  1. The Agent attempts to use the Skill and receives an oo: command not found error.
  2. The Agent follows the first-time setup instructions in SKILL.md.
  3. The applicable command downloads the current contents of install.sh or install.ps1.
  4. Bash or PowerShell executes the response immediately without integrity or authenticity verification beyond transport-level TLS.
  5. If the remote delivery path has been compromised, attacker-controlled installer code executes with the permissions of the user running the Agent.
  6. The payload can inspect accessible local data, modify the environment, install additional software, or misuse existing authenticated sessions and credentials.

...[truncated 667 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace direct pipe-to-shell execution with a staged installation process:

    • Download the installer to a local file.
    • Pin an explicit CLI release version.
    • Verify a vendor-published SHA-256 or stronger checksum.
    • Prefer verification using a trusted code-signing key.
    • Inspect the verified artifact before executing it.
  2. Prefer a trusted, version-pinned package manager or signed release artifact over a mutable installation endpoint.

  3. Require explicit user approval before downloading or executing installation code. The Agent should not install software automatically merely because a command is unavailable.

  4. Document the expected installer source, release version, checksum, signer identity, required permissions, and files or directories modified during installation.

  5. Run the installer with standard user privileges and avoid sudo, administrator PowerShell, or other privilege elevation unless independently justified and explicitly approved.

  6. For PowerShell, download the script as a file and validate its Authenticode signature or published digest before invoking it. For macOS and Linux, perform equivalent signature or checksum validation before running Bash.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
- `delete_opportunity` — Delete a Capsule CRM opportunity. [destructive]
- `delete_party` — Delete a Capsule CRM party. [destructive]
- `delete_task` — Delete a Capsule CRM task. [destructive]
- `get_current_user` — Read the Capsule CRM user associated with the access token.
- `get_opportunity` — Read one Capsule CRM opportunity by ID.
- `get_party` — Read one Capsule CRM party by ID.
- `get_task` — Read one Capsule CRM task by ID.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remotely fetched script without verification. If the install endpoint, transport, DNS, or hosting environment is compromised, arbitrary code could run on the user's machine with the user's privileges; because this appears in an authentication/setup path for a CRM skill, users may be more likely to trust and execute it.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description says to use this skill for "ANY Capsule CRM request" and "Whenever a task involves Capsule CRM," which is an expansive invocation condition without boundaries or negative examples. This can overlap with common planning, discussion, or comparison requests about Capsule CRM rather than only concrete tool-execution tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.