Back to skill

Security audit

Cockroach Labs

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Cockroach Labs read-only connector behavior is coherent, but its fallback setup tells users to execute unverified remote installer scripts directly in a shell.

Install only if you are comfortable trusting OOMOL’s installer endpoint and account connection flow. Prefer installing the oo CLI through a verifiable, version-pinned, or package-manager-based method instead of running the documented pipe-to-shell commands, and review the live schema before allowing any connector action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command streams a remotely hosted shell script directly into Bash. The Skill does not pin the installer to a reviewed version or require signature, checksum, or content verification before execution. Consequently, the code executed at installation time can differ from the content available when the Skill was audited.

Installing the oo CLI is relevant when that required tool is absent, but immediate remote-to-shell execution is not the minimum privilege or safest mechanism necessary to install it. Separating download, verification, inspection, and execution would materially reduce supply-chain risk.

Attack Path

  1. An attacker compromises cli.oomol.com, its deployment pipeline, hosting account, DNS resolution, or another relevant delivery-chain component.
  2. The attacker replaces install.sh with a malicious payload.
  3. A user or agent encounters the documented oo: command not found condition and follows the fallback installation command.
  4. curl downloads the current attacker-controlled response and passes it directly to Bash.
  5. Bash executes the payload without package-version pinning or integrity verification.

Impact Assessment

The downloaded script obtains arbitrary code execution with the privileges of the user running the command. Depending on those privileges and the malicious payload, this could permit access to user-readable files and credentials, modification or destruction of data, installation of persistence, or further network activity. If invoked by a privileged user, the impact could extend to system-wide compromise.

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Prefer a trusted operating-system package manager or a version-pinned release from the CLI's official repository.
  • If a standalone installer is necessary, download it to a non-executable file first.
  • Publish and require verification of a cryptographic signature or version-specific checksum obtained through an independently protected channel.
  • Allow the user to inspect the downloaded script before execution.
  • Execute the installer without elevated privileges unless a documented installation step strictly requires them.
  • Pin the installer or CLI version so the reviewed artifact cannot change silently.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified PowerShell Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell instruction retrieves mutable content from an external URL with Invoke-RestMethod (irm) and immediately executes it with Invoke-Expression (iex). No fixed release, Authenticode validation, detached signature, or cryptographic checksum is required. The effective payload is therefore controlled by whatever the remote endpoint serves when the command runs rather than by the reviewed Skill package.

Although CLI installation supports the declared connector functionality, executing an unverified network response in PowerShell exceeds what is necessary for safe installation.

Attack Path

  1. An attacker compromises the installer endpoint or a relevant part of its delivery chain.
  2. The attacker causes install.ps1 to return malicious PowerShell code.
  3. A Windows user or agent follows the documented fallback after discovering that oo is unavailable.
  4. Invoke-RestMethod retrieves the modified response.
  5. The pipeline passes the response directly to Invoke-Expression, which executes it in the current PowerShell security context without prior integrity validation.

Impact Assessment

Successful exploitation provides arbitrary PowerShell execution under the invoking user's privileges. A malicious installer could read accessible files or credentials, alter user or system configuration, download additional components, destroy data, or establish persistence. Execution from an elevated PowerShell session could lead to system-wide compromise.

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex pattern.
  • Distribute the CLI through a trusted Windows package manager or a version-pinned official release.
  • Download the installer to disk before execution and require explicit user review.
  • Require a valid Authenticode signature or verify a version-specific cryptographic hash through an independently secured channel.
  • Invoke the verified script file directly rather than evaluating a network response with Invoke-Expression.
  • Avoid administrator execution unless a narrowly documented operation requires it.
  • Pin the installer and CLI versions and document a controlled update process.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote-code-execution risk: if the hosting domain, network path, or script content is compromised, arbitrary code will run immediately on the user's system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Cockroach Labs request" and "Whenever a task involves Cockroach Labs," which is very broad and lacks boundaries or exclusion conditions. This can overlap with many ordinary requests that merely mention Cockroach Labs, making activation scope ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.