Back to skill

Security audit

Crowdin

Security checks for vulnerabilities and agentic risk

Overview

The Crowdin integration is mostly clear, but its setup instructions tell users to run a downloaded installer directly, which is risky enough to require review.

Review the installer source and prefer a pinned, verified installation path before using this skill. Once installed, confirm every write or upload payload carefully because the skill can create Crowdin resources and upload source files through an OOMOL-connected account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions download mutable scripts from an external server and immediately execute them using Bash or PowerShell. They do not pin a release version, save the script for inspection, validate a cryptographic checksum, or verify a digital signature.

HTTPS protects data in transit when its trust assumptions hold, but it does not establish that the current script is the same artifact that was security-reviewed. Compromise of the hosting infrastructure, domain or certificate control, deployment pipeline, or maintainer account could replace the script with arbitrary commands. Those commands would execute with all privileges available to the shell that invoked the installer.

Installing a CLI may be relevant to first-time setup, but immediate execution of unverified remote content exceeds the minimum privilege and trust necessary to install it. The documentation also correctly says installation should only be considered after a command-not-found failure, but it does not require explicit approval before executing the installer.

The skill's upload_file action also sends user-selected source files through OOMOL to Crowdin. This network behavior is consistent with the declared Crowdin integration, and the skill requires confirmation for write actions; the reviewed file does not demonstrate covert exfiltration.

Attack Path

  1. The oo CLI is unavailable, causing the documented first-time setup condition.
  2. A user or agent executes one of the provided installation commands.
  3. An attacker who has compromised the remote installation endpoint ...[truncated 1211 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove direct curl | bash and irm | iex installation patterns.
  2. Prefer an official package manager or a version-pinned release artifact from a verifiable distribution channel.
  3. Download the installer to a local file without executing it automatically.
  4. Publish and require verification of a cryptographic checksum and, preferably, a signature tied to a documented release-signing key.
  5. Display or inspect the downloaded script before execution, and require explicit user approval.
  6. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  7. Pin the documented installer to a reviewed version instead of relying on mutable install.sh or install.ps1 endpoints.
  8. Document the files, network destinations, and system changes made by the installer.
  9. For example, use a workflow equivalent to:
bash
curl -fSLo oo-install.sh "https://trusted.example/releases/vX.Y.Z/install.sh"
echo "<published-sha256>  oo-install.sh" | sha256sum --check -
less oo-install.sh
bash oo-install.sh

The checksum must be obtained through a separately authenticated release process; placing an untrusted checksum beside the mutable installer would not provide meaningful protection.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote-code-execution risk because any compromise of the hosting domain, transport path, or script contents would execute arbitrary code immediately on the user's machine without inspection.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Static analysis

No suspicious patterns detected.