Back to skill

Security audit

Merriam-Webster Collegiate

Security checks for vulnerabilities and agentic risk

Overview

The skill’s dictionary lookup purpose is coherent, but its setup instructions tell users to run unverified remote installer scripts directly in Bash or PowerShell.

Review the installation step before using this skill. The lookup action itself is read-only, but if `oo` is missing the skill points to installer commands that execute code fetched live from OOMOL; prefer a verified package, checksum/signature validation, or manual inspection before running those commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:55
Finding

Unverified Remote Bash Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The setup instruction downloads a mutable script from cli.oomol.com and passes it directly to Bash without first saving, inspecting, or cryptographically verifying it. HTTPS protects the connection in transit but does not pin the installer content or guarantee that future content at the URL will match what was reviewed.

If the domain, hosting infrastructure, CDN, DNS path, deployment credentials, or installer publishing process is compromised, the remote script can be replaced with arbitrary commands. Those commands would execute with the permissions of the user following the installation instruction.

Installing a CLI may be necessary for the connector-based design, but immediate execution of an unpinned remote payload exceeds the minimum privileges and trust required to perform the declared dictionary lookup. The audited project supplies no fixed release version, checksum, signature, or local installer copy.

Attack Path

  1. The oo CLI is absent, and the user follows the first-time setup instruction.
  2. An attacker compromises or otherwise gains control over the content returned by https://cli.oomol.com/install.sh.
  3. curl retrieves the attacker-controlled script.
  4. The pipe sends the response directly to Bash without verification or review.
  5. Bash executes the payload with the invoking user's privileges.
  6. The payload can read accessible data, alter files, install additional software, or establish persistence.

Impact Assessment

Successful exploitation provides arbitrary command execution within the invoking user's security context. The attacker could access local files and credentials available to that user, modify user-owned configuration or ex ...[truncated 354 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Prefer a trusted operating-system package manager and pin the CLI to an exact reviewed version.
  • If a standalone installer is required, download a versioned artifact to disk before execution.
  • Publish and require verification of a pinned cryptographic checksum and, preferably, a signature tied to a documented signing key.
  • Keep installation separate from autonomous Skill execution and require explicit user approval before running any installer.
  • Display the artifact source, version, checksum, requested privileges, and expected changes before execution.
  • Document a manual inspection procedure and provide reproducible release artifacts.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote PowerShell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell setup instruction uses Invoke-RestMethod (irm) to retrieve a mutable remote script and immediately executes the returned text through Invoke-Expression (iex). This prevents meaningful inspection or integrity verification before execution.

HTTPS alone does not establish that the downloaded script is a specific reviewed release. Compromise of the remote publishing account, hosting service, domain, CDN, DNS path, or deployment pipeline could cause arbitrary PowerShell code to be returned and executed.

This is particularly dangerous because PowerShell can access the filesystem, user credentials and configuration, the registry, network resources, and system-management interfaces available to the current security context. The project provides no pinned version, Authenticode validation requirement, checksum, or reviewable local script.

Attack Path

  1. The oo CLI is absent on a Windows system, and the user follows the documented first-time setup.
  2. An attacker modifies or controls the response from https://cli.oomol.com/install.ps1.
  3. irm downloads the malicious PowerShell source as response content.
  4. The pipeline passes that content directly to iex.
  5. iex evaluates the payload in the current PowerShell session.
  6. The attacker performs actions allowed by the user's token, such as reading files, changing configuration, installing additional payloads, or creating persistence.

Impact Assessment

Exploitation results in arbitrary PowerShell execution with the invoking user's privileges. It can expose accessible files, credentials, connection information, and network resources; modify user or system settings; and install ...[truncated 295 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Distribute the CLI through a trusted Windows package manager using an exact, reviewed version.
  • Alternatively, download the installer to disk and require verification before execution.
  • Require a pinned SHA-256 or stronger digest and validate an Authenticode or equivalent publisher signature against a documented trusted certificate.
  • Avoid Invoke-Expression; execute only a verified, versioned artifact using an explicit command.
  • Require explicit user authorization and disclose the installer's requested privileges and expected system changes.
  • Do not recommend launching the installer from an elevated shell unless elevation is demonstrably necessary and narrowly scoped.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into bash, which executes unverified code from the network without prior inspection or integrity verification. In a skill context, this is especially risky because the content is operational guidance that an agent or user may follow automatically, turning a documentation pattern into a practical remote code execution path if the upstream server, transport, or installer is compromised.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Static analysis

No suspicious patterns detected.