Back to skill

Security audit

Cloudinary

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Cloudinary use, but its setup instructions tell users to run an unverified internet installer directly in a shell.

Review the oo CLI installation path before installing. Prefer a verified package, pinned release, checksum, or signed installer, and only approve write actions after checking the exact Cloudinary asset and payload that will be changed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions download mutable content from an external server and immediately pass it to a command interpreter. The Unix command pipes the HTTP response directly into Bash, while the Windows command evaluates the downloaded PowerShell content through iex.

No version pinning, cryptographic checksum validation, digital-signature verification, or opportunity for local inspection is provided. Although HTTPS protects the connection in transit, it does not ensure that the delivered script remains identical to the version reviewed. A compromise of the remote server, hosting account, deployment pipeline, or associated infrastructure could therefore change the effective payload at any time.

Installing the CLI may be relevant to the skill's declared Cloudinary functionality, but immediate execution of an unverified remote response exceeds the minimum privileges and safeguards necessary to perform that installation.

Attack Path

  1. The oo command is unavailable, causing the agent or user to consult the first-time setup instructions.
  2. An attacker compromises the installer endpoint, its deployment pipeline, or another component capable of controlling the returned script.
  3. The victim runs the documented curl | bash or irm | iex command.
  4. The attacker-controlled response is supplied directly to the local shell without integrity verification.
  5. Arbitrary commands execute with th ...[truncated 855 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that pipe downloaded content directly into Bash or evaluate it with PowerShell.
  2. Direct users to a version-pinned release artifact from the official distribution channel.
  3. Download the installer or binary to a local file without executing it automatically.
  4. Publish and require verification of a cryptographic checksum from a separately authenticated source.
  5. Prefer signed release artifacts and validate the publisher's digital signature before execution.
  6. Allow the user to inspect the downloaded installer and require explicit approval before running it.
  7. Run installation with ordinary user privileges unless a specific installation step demonstrably requires elevation.
  8. Document the files, commands, network destinations, and configuration changes performed by the installer.
  9. Where supported, recommend a trusted package manager with a pinned package version and signature-verification controls.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell (curl ... | bash), which executes unverified code from the network without integrity checking or review. If the install endpoint, transport, or upstream distribution is compromised, this can lead to arbitrary code execution on the host running the skill setup.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says to use this skill for "ANY Cloudinary request" and "Whenever a task involves Cloudinary," which is a very broad activation condition without boundaries or exclusion examples. That can overlap with many loosely related tasks and makes it unclear when the skill should or should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.