Back to skill

Security audit

Chatwork

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Chatwork connector, but its first-time setup tells users to execute remote installer scripts directly, which is a meaningful local security risk.

Review the installer source before running it, prefer a signed or checksum-verified oo CLI installation method, and require explicit approval before any Chatwork write or delete action. The connector behavior itself is understandable, but the setup commands should be treated carefully.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:69
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable shell script from an external URL and pipes it directly into Bash. The remote response is executed without version pinning, checksum validation, cryptographic signature verification, or an opportunity to inspect the downloaded file.

Although the endpoint uses HTTPS and its domain is consistent with the named vendor, those properties do not guarantee the integrity of future responses. The effective executable payload can change after the Skill has been reviewed. Compromise of the hosting account, installer infrastructure, domain resolution, or relevant TLS trust chain could therefore turn this command into an arbitrary-code execution channel.

Installing the required CLI may be necessary for the declared Chatwork connector functionality, but immediate execution of an unverified remote response exceeds the minimum safe installation procedure.

Attack Path

  1. A Chatwork operation fails because the oo CLI is not installed.
  2. The user or Agent follows the documented first-time setup instruction.
  3. curl retrieves the current response from https://cli.oomol.com/install.sh.
  4. The response is passed directly to Bash without integrity verification or review.
  5. If the remote installer or delivery infrastructure has been compromised, attacker-controlled shell commands execute immediately.
  6. Those commands can perform any operation available to the account that invoked Bash.

Impact Assessment

A malicious installer response can obtain arbitrary code execution with the privileges of the invoking user. It could read or modify accessible files, access environment variables and locally a ...[truncated 282 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Pin installation instructions to a specific, reviewed CLI release rather than a mutable installer endpoint.
  • Download the installer or release artifact to a local file before execution.
  • Publish and verify a cryptographic signature or a checksum obtained through an independently authenticated channel.
  • Prefer a trusted platform package manager with signed packages where available.
  • Display the exact artifact version, source, and expected digest to the user.
  • Require explicit user approval before executing any installer.
  • Run installation with ordinary user privileges unless a documented component strictly requires elevation.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:73
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 73
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup instruction uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script and sends the response directly to Invoke-Expression (iex). Invoke-Expression interprets the downloaded text as PowerShell code immediately. No fixed release, checksum, signature verification, or local inspection step is provided.

HTTPS protects transport under normal conditions but does not make mutable server content independently verifiable. A compromised hosting endpoint, vendor account, domain resolution path, or applicable TLS trust chain could supply attacker-controlled PowerShell. The payload can also change after the Skill package has passed review.

The Skill legitimately needs a compatible CLI to provide its declared Chatwork integration, but executing an unauthenticated remote response through iex is not the least-risk installation mechanism.

Attack Path

  1. A Chatwork action fails on Windows because the oo CLI is unavailable.
  2. The user or Agent follows the first-time setup documentation.
  3. Invoke-RestMethod downloads the current content of https://cli.oomol.com/install.ps1.
  4. The pipeline passes that content directly to Invoke-Expression.
  5. If the endpoint or delivery path has been compromised, attacker-supplied PowerShell executes without verification.
  6. The payload can then use all resources and permissions available to the PowerShell process.

Impact Assessment

Successful exploitation provides arbitrary PowerShell execution under the invoking account. An attacker could access user-readable files and credentials, modify user configuration, install additional payloads, invoke operat ...[truncated 256 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Direct users to a specific, reviewed, signed CLI release or a trusted signed package repository.
  • Download the PowerShell script or package to disk before execution.
  • Validate its Authenticode signature and a published cryptographic digest.
  • Present the pinned version, expected publisher, source URL, and digest to the user.
  • Require explicit approval after verification and before execution.
  • Avoid administrator privileges unless a documented installation step strictly requires them.
  • Consider installation through a package manager that verifies publisher identity and package integrity.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the install endpoint, transport, hosting, or upstream release process is compromised, arbitrary code will execute on the host without prior inspection.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Chatwork request" and "Whenever a task involves Chatwork," which is a very broad trigger that overlaps with many ordinary requests involving Chatwork. It does not provide scope constraints, exclusions, or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.