Back to skill

Security audit

Contentstack Content Delivery

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent read-only Contentstack connector, but its first-time setup tells users to execute an unverified remote installer script.

Review the first-time setup carefully before installing. Prefer installing the oo CLI through a verifiable package manager or an official versioned installer with checksum/signature verification, and do not run the installer as administrator/root unless you have independently verified what it does. Once the CLI is installed, the skill's Contentstack actions appear limited to read-only get/list operations.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Remote CLI Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis Both installation commands retrieve mutable code from an external server and immediately execute it in a local command interpreter. Neither command pins a version, verifies a cryptographic signature, checks a known digest, nor gives the user an opportunity to inspect the downloaded script before execution. HTTPS authenticates the server connection under normal conditions, but it does not establish that the current script is identical to the version reviewed with this Skill. If the hosting domain, deployment pipeline, DNS resolution, TLS trust chain, or upstream account is compromised, the returned script can be replaced without any change to `SKILL.md`. The commands are documented as conditional first-time setup rather than routine execution, and the domain appears consistent with the declared OOMOL service. Nevertheless, source consistency does not eliminate the remote-code-execution boundary. Installing the CLI is also separate from the Skill's core read-only Contentstack operations and should not occur through an unverified execution pipeline. The connector commands elsewhere in the file necessarily transmit action payloads to the declared OOMOL/Contentstack connector service. The document states that credentials are injected server-side and does not expose raw tokens. Based on the available file, that declared network behavior is necessary for the Skill's functionality and is not independently classified as a vulnerability. ...[truncated 1699 chars]
Remediation
View remediation
/install.sh' ``` 4. Publish a version-specific SHA-256 digest or, preferably, a detached signature verified against a pinned vendor signing key. Verify it before execution: ```bash echo ' oo-install.sh' | sha256sum --check less oo-install.sh bash oo-install.sh ``` 5. Apply the equivalent controls on Windows: download a versioned script, validate an Authenticode signature or pinned cryptographic digest, allow inspection, and only then execute it. 6. Document the expected files, network destinations, and configuration changes made by the installer. 7. Explicitly instruct users not to run the installer as root or Administrator unless a documented operation strictly requires elevation. 8. Keep installation outside normal Skill execution. If `oo` is unavailable, return a clear prerequisite error rather than automatically retrieving or executing remote code. 9. Pin the CLI version used with the Skill and provide an authenticated update process so upstream changes cannot silently alter the reviewed execution path. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell (curl ... | bash), which is a classic supply-chain and arbitrary code execution risk. If the install endpoint, transport, DNS, or hosting account is compromised, a user following this guidance could execute attacker-controlled code on their machine with their own privileges.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documents the skill as a Contentstack Content Delivery tool for 'searching and reading data' and lists only read operations in the Available actions section. However, the Safety section and nearby guidance discuss write and destructive actions changing state, which contradicts the documented action set and stated read-only intent rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.