Back to skill

Security audit

Close

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Close CRM connector, but its first-time setup tells users to execute a remote installer directly, which deserves Review before installation.

Review the oo CLI installation path before using this skill. Prefer installing the CLI from a verified, pinned, or signed source rather than running the pasted remote installer commands directly; once installed, confirm any Close create or update payload before allowing it to run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:70
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 70–74
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from cli.oomol.com and pass them directly to a command interpreter. The Unix command pipes the HTTP response into Bash, while the Windows command passes the response to PowerShell's Invoke-Expression.

Neither installation path pins a release version, verifies a cryptographic signature or checksum, nor provides an opportunity to inspect the downloaded script before execution. HTTPS protects data in transit but does not protect against a compromised distribution server, publishing account, DNS or certificate infrastructure, or an unexpectedly modified upstream installer.

The effective executable payload can therefore change after the Skill package has been audited. Although installation is presented as a fallback for when oo is unavailable, remote script execution is not required during ordinary connector operations and exceeds the minimum privileges needed for the Skill's normal Close CRM functionality.

Attack Path

  1. The user or agent attempts to invoke the Skill on a system where the oo CLI is not installed.
  2. The documented first-time setup procedure is selected.
  3. An attacker compromises the installer host, its deployment pipeline, or another part of the trusted delivery chain and replaces the installer with malicious content.
  4. curl or Invoke-RestMethod downloads the current remote response.
  5. Bash or PowerShell executes the response immediately without integrity verification or review.
  6. The payload performs arbitrary actions with the privileges of the user running the installation c ...[truncated 803 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove direct curl | bash and irm | iex installation commands from the Skill instructions.
  2. Direct users to a version-pinned release artifact or a trusted operating-system package manager instead of a mutable installer endpoint.
  3. Require the artifact to be downloaded to disk before execution so that it can be inspected.
  4. Publish a SHA-256 or stronger checksum through an independently protected release channel and verify it before running the installer.
  5. Prefer cryptographically signed packages and verify the publisher signature and signing-chain validity.
  6. Keep installation outside autonomous Skill execution. The Skill should stop and ask the user to complete the verified installation procedure manually.
  7. Run installation without administrator privileges unless a documented component strictly requires elevation.
  8. Apply equivalent version pinning, signature validation, and manual review requirements to both the Bash and PowerShell installation paths.
  9. Document the files, permissions, network endpoints, and persistence mechanisms used by the installer so users can evaluate the requested privileges.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs piping a remotely fetched installer directly into a shell (curl ... | bash), which executes unverified code from the network with the user's privileges. If the install script, hosting infrastructure, DNS/TLS path, or upstream distribution process is compromised, this becomes a straightforward remote code execution path.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY Close request," including reading, creating, and updating data. This is a very broad activation scope that could overlap with many ordinary CRM-related requests without clearly defining boundaries or exclusions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.