Back to skill

Security audit

DataScope

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent DataScope connector, but its first-time setup tells users or agents to run unverified remote installer scripts directly in a shell.

Review the installation steps before use. Prefer installing the oo CLI through verified official documentation or a package manager, and do not let an agent run the remote installer automatically. For normal DataScope write actions, confirm the exact records and payload before allowing changes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63–67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from cli.oomol.com and pass their contents directly to Bash or PowerShell. The scripts are executed without first saving them for inspection, pinning an immutable release, or verifying a cryptographic signature or digest.

The installer files are not included in the audited project, so their contents and behavior cannot be assessed from the repository. Although the host is consistent with the declared OOMOL service, these commands establish an external code-execution channel whose effective payload can change after the Skill has been reviewed.

This capability exceeds what is necessary for routine DataScope operations. Normal use requires only the allowlisted oo CLI commands, while the installation fallback can execute arbitrary commands with all permissions of the invoking user.

Attack Path

  1. The oo CLI is absent, causing the user or agent to follow the first-time setup instructions.
  2. An attacker compromises the installer publication process, hosting infrastructure, domain resolution, or another trusted delivery component associated with cli.oomol.com.
  3. The attacker replaces or modifies install.sh or install.ps1 with a malicious payload.
  4. curl or irm retrieves the attacker-controlled response.
  5. The shell pipeline passes the response directly to Bash or PowerShell without integrity verification or inspection.
  6. The payload executes with the permissions of the invoking user.

Impact Assessment

Successful exploitation provides arbitrary code execution in the user context. The payload could read ...[truncated 546 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all pipe-to-shell and download-to-Invoke-Expression installation instructions.
  • Prefer a trusted operating-system package manager or a formally published, version-pinned CLI package.
  • If direct installation artifacts are necessary:
    1. Pin a specific immutable CLI release and artifact URL.
    2. Download the artifact to disk without executing it.
    3. Publish a SHA-256 digest or cryptographic signature through a separately authenticated channel.
    4. Verify that digest or signature before execution.
    5. Permit inspection and require explicit user approval before running the installer.
  • Run installation with ordinary user privileges unless elevation is strictly necessary and clearly justified.
  • Document the files, permissions, network destinations, and system changes expected from the installer.
  • Keep installation outside automated Skill execution; the Skill should report the missing dependency and direct the user to verified manual installation documentation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash), which creates a trust-on-first-use remote code execution path. If the install endpoint, transport, DNS, or hosting supply chain is compromised, arbitrary code could run on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY DataScope request," covering reading, creating, and updating data. This is broad enough to trigger on any mention of DataScope without clarifying boundaries, exclusions, or negative examples, which can cause unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.