Back to skill

Security audit

Coinbase

Security checks for vulnerabilities and agentic risk

Overview

The Coinbase skill is mostly coherent and read-only, but it needs Review because its setup instructions execute unverified remote installer scripts and its routing language is broader than its documented actions.

Install only if you are comfortable using OOMOL as an intermediary for Coinbase account lookups. Avoid running the one-line installer commands unless you independently trust and verify the oo CLI installer; prefer a signed or pinned installation path. Confirm the skill is used only for the documented read-only account actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis
Remediation
View remediation
/install.sh # Verify the publisher's cryptographic signature before continuing. bash install.sh ``` Checksum verification alone is only meaningful if the expected checksum is obtained from a separately trusted and immutable source. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis
Remediation
View remediation
/install.ps1" ` -OutFile ".\install.ps1" Get-AuthenticodeSignature ".\install.ps1" # Continue only if the signature is valid and belongs to the expected publisher. .\install.ps1 ``` ]]>

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:3
Finding

Overbroad Coinbase Request Routing Through a Third-Party Connector

Content
View full analysis
" --data '' --json ``` ### Technical Analysis The Skill instructs the agent to use OOMOL for “ANY Coinbase request” and to avoid calling Coinbase directly. This changes the routing decision for an entire service rather than limiting activation to the two documented read operations, `get_account` and `list_accounts`. The document discloses that OOMOL supplies credentials server-side, and there is no evidence that raw Coinbase tokens are exposed to the agent. Nevertheless, request payloads and Coinbase responses necessarily pass through or are processed by the OOMOL connector infrastructure. These may include Coinbase account UUIDs, accessible account information, request metadata, and OOMOL execution identifiers. Using an intermediary is intrinsic to the declared connector design, but the unconditional routing instruction is broader than the listed functionality and does not preserve a direct-API option. It therefore exceeds the narrowest routing privileges needed for the declared read actions. ### Attack Path 1. A ...[truncated 1454 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill includes a one-line remote installation command that fetches a script over the network and pipes it directly to a shell. If the install endpoint, transport, publisher account, or distribution path is compromised, an agent or user following this guidance could execute arbitrary code on the local system.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text says to use this skill for ANY Coinbase request and instead of calling the API directly, which is broader than the actual safe capability set described later. This can cause the agent to route unrelated, unsupported, or higher-risk Coinbase tasks through this skill by default, increasing the chance of incorrect tool use, accidental setup actions, or misleading user expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.