Back to skill

Security audit

CollegeFootballData

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent CollegeFootballData connector, but its setup path asks users to run unverified remote installer scripts.

Review the setup instructions carefully before installing. If the oo CLI is already installed and authenticated, normal use appears limited to CollegeFootballData connector reads. If installation is needed, avoid piping a downloaded script directly into a shell; prefer a verified, versioned installer or documented package source, and understand that OOMOL account connection is required.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Remote Shell Script Downloaded and Executed Without Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:59
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions retrieve a shell script from https://cli.oomol.com/install.sh and pipe the response directly into Bash. The script is neither included in the reviewed project nor pinned to an immutable version or digest. Consequently, its effective behavior cannot be determined from the audited artifact and can change after review.

HTTPS protects the connection in transit but does not mitigate compromise of the hosting service, DNS or certificate infrastructure, the publisher account, or the remote deployment pipeline. It also does not prevent the publisher from replacing the script later. Directly piping the response into Bash removes the opportunity to inspect the downloaded artifact or verify its checksum or signature before execution.

Installing the CLI may be necessary when it is absent, but immediate execution of a mutable remote payload is not the minimum-privilege mechanism required for the Skill's declared read-only football-data functionality.

Attack Path

  1. The oo CLI is unavailable, or the user is induced to treat it as unavailable.
  2. The agent or user follows the first-time setup command in SKILL.md.
  3. An attacker compromises or controls the remote installer, its delivery infrastructure, or the publisher's deployment process.
  4. curl retrieves the attacker-controlled response.
  5. The pipe sends the response directly to Bash without local review, version pinning, checksum validation, or signature verification.
  6. Bash executes the payload with the privileges of the current user.

Impact Assessment

The remote payload obtains arbitrary command-execution capability under the current user's account. Depending on that account ...[truncated 469 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the pipe-to-shell command with a version-pinned installer obtained from a trusted release page or package repository.
  • Download the artifact to disk without executing it, then verify a publisher signature and a cryptographic digest distributed through an independent trusted channel.
  • Display the exact version, source, expected digest, and requested privileges before installation.
  • Require explicit user approval before executing installation commands.
  • Run the installer without elevated privileges unless elevation is strictly required and separately justified.
  • Prefer a reproducible package-manager installation with locked versions and package-signature verification.
  • If a script remains necessary, vendor and audit the exact script or reference an immutable, digest-addressed release rather than a mutable URL.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Remote PowerShell Script Executed Through Invoke-Expression Without Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:63
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup command uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script and pipes its text directly into Invoke-Expression (iex). This causes unreviewed network content to be interpreted as PowerShell code immediately.

The project does not include the installer, identify an immutable release, pin a digest, or require Authenticode signature verification. The payload can therefore change independently of the reviewed Skill. Invoke-Expression creates a direct arbitrary-code execution channel and prevents meaningful pre-execution inspection.

Although installing the connector CLI may be necessary when absent, executing mutable network content with the user's full PowerShell privileges exceeds the minimum privileges needed for the declared read-only connector operations.

Attack Path

  1. The oo CLI is unavailable on a Windows host, or the user is induced to reinstall it.
  2. The agent or user follows the PowerShell setup command.
  3. An attacker compromises or controls the remote script, hosting environment, publisher account, or delivery infrastructure.
  4. Invoke-RestMethod downloads attacker-controlled PowerShell source.
  5. The pipeline passes the source directly to Invoke-Expression, without version, digest, or signature verification.
  6. PowerShell executes the payload with the current process's privileges.

Impact Assessment

The payload can execute arbitrary PowerShell and native commands with the permissions of the current user. It could access user-readable documents and credentials, modify profile or application settings, download further payloads, communicate with external services, or configure persistence. Exec ...[truncated 272 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex pattern.
  • Use a signed, version-pinned MSI, MSIX, or PowerShell package from a trusted immutable release.
  • Download the installer separately and verify its SHA-256 digest and Authenticode publisher signature before execution.
  • Require explicit user confirmation after showing the source, version, signature identity, digest, and requested privilege level.
  • Do not request administrator privileges unless a documented installation step strictly requires them.
  • If PowerShell scripting is unavoidable, store the verified script locally and execute it with a constrained, documented invocation rather than Invoke-Expression.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill recommends installing software via curl ... | bash, which executes a remotely fetched script directly in the shell without prior verification. If the remote server, transport, or distribution pipeline is compromised, this can lead to arbitrary code execution on the user's machine; because it appears in a fallback setup path inside a trusted skill, users may be more likely to follow it without scrutiny.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use this skill for "ANY CollegeFootballData request" and "Whenever a task involves CollegeFootballData," which is a very broad activation condition without scope limits or negative examples. In a manifest-like markdown file, this can overlap with many routine references to the service and makes it unclear when the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.