Back to skill

Security audit

Codacy

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only Codacy connector, but its setup instructions can execute remote installer scripts directly without verification.

Review this skill before installing. It appears intended for read-only Codacy access, but do not let an agent run the provided installer commands automatically; install the oo CLI only through a source and process you trust, preferably with a pinned version or verified installer.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Remote Shell Script Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command retrieves a mutable shell script from an external server and pipes it directly into bash. The downloaded payload is neither pinned to a specific version nor verified using a cryptographic signature or trusted checksum. It is also not saved for inspection before execution.

Although HTTPS protects the connection in transit under normal circumstances, it does not establish payload immutability or protect users if the distribution server, DNS infrastructure, certificate authority, or publisher account is compromised. Because the effective script can change after the Skill has been reviewed, its behavior cannot be determined from the package itself.

The instruction is only used as a fallback when the oo command is unavailable, but installing the CLI through an immediately executed remote script exceeds the minimum privilege required merely to document how Codacy queries are performed.

Attack Path

  1. The Agent attempts to use the declared oo CLI and receives an oo: command not found error.
  2. The Agent follows the first-time setup instruction in SKILL.md.
  3. curl retrieves the current contents of https://cli.oomol.com/install.sh.
  4. The downloaded content is passed directly to bash without validation or inspection.
  5. If the hosting service or delivery chain has been compromised, attacker-controlled commands execute with the privileges of the user running the Agent.
  6. The payload could then read accessible data, alter user files, install additional software, access credentials available to the process, or establish persistence.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. The reachable s ...[truncated 378 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Link users to a documented, manual installation procedure rather than allowing an Agent to execute an installer automatically.
  • Pin the CLI to a specific, reviewed release and download the corresponding immutable artifact.
  • Publish and verify a cryptographic signature or a checksum obtained through a trusted, independent channel.
  • Save the artifact locally and allow inspection before execution.
  • Require explicit user approval before running any installer.
  • Run installation with ordinary user privileges and avoid requesting administrative access unless a documented component strictly requires it.
  • Prefer a trusted operating-system package manager with signed packages and version pinning where available.
  • Document the expected files, permissions, and network endpoints used by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Remote PowerShell Script Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell installation command uses Invoke-RestMethod (irm) to retrieve a mutable script and passes the response directly to Invoke-Expression (iex). This causes the downloaded text to be interpreted as PowerShell code without version pinning, signature validation, checksum verification, local review, or an opportunity to inspect the effective payload.

The command creates a remote code-execution channel whose contents may change after the Skill is audited. HTTPS alone does not guarantee that the hosted script remains identical to a previously reviewed version and does not mitigate compromise of the publisher or distribution infrastructure.

This behavior is presented as a conditional first-time installation fallback. Nevertheless, immediate execution is not necessary: the Skill could instead direct the user to a pinned, signed release and require deliberate installation approval.

Attack Path

  1. The Agent or user finds that the oo CLI is not installed on Windows.
  2. The first-time setup instructions are followed.
  3. Invoke-RestMethod downloads the current response from https://cli.oomol.com/install.ps1.
  4. The response is piped directly into Invoke-Expression.
  5. If an attacker controls the hosted payload or compromises its delivery path, arbitrary PowerShell commands execute in the current process context.
  6. The commands could access user data and credentials, modify PowerShell profiles, install software, create persistence mechanisms, or perform other actions permitted to the current Windows account.

Impact Assessment

Successful exploitation grants arbitrary PowerShell execution with the privileges of the invoking account. This may expose accessible local fi ...[truncated 375 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Download a version-pinned installer or package without executing it immediately.
  • Require Authenticode signature validation against an explicitly trusted publisher certificate.
  • Publish and verify a cryptographic checksum through a trusted channel.
  • Prefer a signed package distributed through a trusted Windows package manager.
  • Present the artifact and intended changes to the user and obtain explicit approval before execution.
  • Avoid elevation by default and document any operation that genuinely requires administrative privileges.
  • Document expected installation paths, registry changes, profile modifications, and network destinations.
  • Fail closed if signature, checksum, publisher, or version validation does not succeed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install the CLI via curl ... | bash, which executes a remote script directly without verification. If the install endpoint, transport, or hosting is compromised, this becomes arbitrary code execution on the user's machine; because this is in a troubleshooting/setup path, an agent may surface it during normal operation and amplify the risk.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description uses a very broad activation condition: any task that "involves Codacy" should use this skill. This lacks clear scope boundaries or exclusion examples, so ordinary references to Codacy could trigger the skill even when direct use is unnecessary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.