Back to skill

Security audit

Cloudflare DNS

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Cloudflare DNS, but its first-time setup tells users to execute remote installer scripts directly without integrity checks.

Install only if you trust OOMOL and the oo CLI installer. Prefer a package manager or a downloaded, version-pinned installer with checksum or signature verification, and use least-privileged Cloudflare access. Carefully review and approve any DNS write or delete payload before it runs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Remote Shell Script Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Unverified remote payload execution through a shell
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command pipes a mutable network response directly into bash. It does not pin a release version, verify a cryptographic checksum or publisher signature, or provide an opportunity to inspect the downloaded script before execution.

HTTPS protects the connection in transit but does not guarantee that the server, publishing pipeline, or hosted script remains trustworthy. Because the effective payload is retrieved at execution time, it can change after the Skill has been reviewed. The installer also runs with all privileges available to the user launching the command.

This behavior is not necessary at the requested privilege level. Installing a CLI may be necessary for the Skill, but immediately executing an unverified remote response is not the minimum-privilege or minimum-risk installation method.

Attack Path

  1. The oo CLI is absent and the action fails with oo: command not found.
  2. The user or agent follows the documented first-time setup command.
  3. An attacker compromises the installer host, DNS resolution, TLS termination, or the vendor's script-publishing pipeline.
  4. The endpoint returns an attacker-controlled shell script.
  5. curl streams the response directly to bash, which executes it without integrity validation or review.
  6. The payload performs arbitrary actions under the invoking user's account.

Impact Assessment

Successful exploitation provides arbitrary command execution with the privileges of the user running the installation command. An attacker could read or modify user-accessible files, steal environment variables and local credentials, alter shell configuration, install pers ...[truncated 388 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash execution pattern.
  • Prefer an official platform package manager or a version-pinned release artifact from a documented vendor repository.
  • Download the installer or binary to a local file before execution.
  • Pin an expected release version and verify a vendor-published cryptographic signature and a trusted SHA-256 or stronger digest.
  • Fail closed if signature or checksum validation does not succeed.
  • Allow the user to inspect the downloaded artifact and request explicit approval before executing it.
  • Run installation without administrator privileges unless a specific installation step demonstrably requires elevation.
  • Document the files, network endpoints, and system changes made by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Remote PowerShell Script Downloaded and Executed Through Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: Unverified remote payload execution through PowerShell
Risk Level: High

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

irm retrieves content from a mutable external URL and pipes it directly to iex, an alias for Invoke-Expression. Invoke-Expression interprets the downloaded response as PowerShell code in the current process. No release version, checksum, Authenticode signature, or other independent integrity control is verified before execution.

The remote server therefore controls the code executed by the command. Even though the URL uses HTTPS, compromise of the host or publishing infrastructure can replace the installer with arbitrary PowerShell. Direct interpretation of the response also eliminates the normal separation between downloading, validating, reviewing, and executing an artifact.

Installing the required CLI may support the declared functionality, but executing mutable remote content through Invoke-Expression exceeds the minimum risk and trust required for installation.

Attack Path

  1. A Windows user encounters a missing oo CLI.
  2. The user or agent follows the PowerShell setup instruction.
  3. An attacker gains control of the installer endpoint or an upstream component capable of changing its response.
  4. Invoke-RestMethod downloads the attacker's PowerShell payload.
  5. The pipeline passes the payload directly to Invoke-Expression.
  6. PowerShell executes the payload with the current process token and user privileges.

Impact Assessment

Exploitation enables arbitrary PowerShell execution under the invoking user's security context. The payload could access user-readable files, browser or application data, environment variables, and available authentication material; modify user configuration; ins ...[truncated 346 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern and avoid Invoke-Expression for downloaded content.
  • Prefer a signed and version-pinned package distributed through a trusted Windows package source.
  • Otherwise, save the installer to disk and verify its Authenticode signature, signer identity, pinned version, and cryptographic digest before execution.
  • Abort installation if any verification fails.
  • Present the verified artifact and its expected changes to the user, then obtain explicit approval before running it.
  • Execute with a non-administrative token by default and request elevation only for narrowly identified operations that require it.
  • Publish reproducible release artifacts and document an independently verifiable integrity-validation procedure.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs users to install the CLI by piping a remotely fetched script directly into a shell (curl ... | bash). This is dangerous because it executes unaudited code from the network immediately, so a compromised host, CDN, domain, or MITM condition could result in arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Static analysis

No suspicious patterns detected.