Back to skill

Security audit

DialMyCalls

Security checks for vulnerabilities and agentic risk

Overview

The skill’s DialMyCalls connector behavior is mostly coherent, but its setup instructions include unverified remote installer commands that could execute arbitrary code if followed.

Review the installer path before installing. Prefer installing the oo CLI from a verified, versioned source with checksum or signature validation, and only approve DialMyCalls write or delete actions after checking the exact target and payload.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Unverified Remote Installation Script Executed Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a script from an external URL and pipes it directly into Bash. The script is neither pinned to an immutable version nor validated using a cryptographic signature or checksum. Consequently, the code executed on the local system can change after the Skill has been reviewed.

HTTPS protects the connection in transit but does not guarantee that the hosting account, server, DNS configuration, or installation script remains trustworthy. Although installing the oo CLI supports the Skill's declared functionality, immediate execution of mutable remote content is not the minimum safe installation method.

Attack Path

  1. An attacker compromises the installation host, its deployment pipeline, hosting account, or another component capable of modifying https://cli.oomol.com/install.sh.
  2. The attacker replaces or modifies the installation script with malicious shell commands.
  3. The oo command is unavailable, causing the documented first-time setup path to be used.
  4. The command downloads the attacker-controlled response and passes it directly to Bash.
  5. Bash executes the payload with the privileges of the user running the Agent.

Impact Assessment

Successful exploitation permits arbitrary command execution under the invoking user's account. Depending on that account's permissions and the payload, an attacker could read or modify local files, access environment variables and credentials, alter installed tools, exfiltrate sensitive information, or attempt persistence and further privilege escalation. The evidence does not establish that the current remote script is malicious, but the unverified execution channel ...[truncated 40 chars]

Remediation
View remediation

Remediation Suggestions

Remove the pipe-to-shell installation command. Install the CLI through a trusted package manager using a pinned version, or use the following controlled process:

  1. Download a versioned release artifact without executing it.
  2. Verify its SHA-256 checksum against a value delivered through a separately trusted channel.
  3. Verify a publisher signature where available.
  4. Inspect the downloaded installer before execution.
  5. Execute it without elevated privileges unless elevation is demonstrably required.
  6. Document the exact version and trusted release source so future audits evaluate an immutable artifact.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:70
Finding

Unverified Remote PowerShell Script Executed Through Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 70
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

irm retrieves content from the remote installation endpoint and pipes it into iex (Invoke-Expression), which evaluates the response as PowerShell code immediately. No immutable version, expected checksum, Authenticode signature verification, or review step is specified.

This makes the effective payload dependent on mutable external content rather than the audited Skill package. Compromise of the endpoint or its publishing infrastructure could therefore turn a legitimate setup instruction into arbitrary local code execution. Installing the required CLI is functionally relevant, but direct Invoke-Expression of a network response exceeds the minimum privileges and trust necessary for installation.

Attack Path

  1. An attacker gains the ability to alter the content returned by https://cli.oomol.com/install.ps1.
  2. The attacker inserts malicious PowerShell commands into the installer.
  3. A Windows user encounters an oo: command not found condition and follows the documented setup command.
  4. Invoke-RestMethod downloads the modified response.
  5. Invoke-Expression executes the response in the active PowerShell session with the user's privileges.

Impact Assessment

Successful exploitation enables arbitrary PowerShell execution as the invoking user. A malicious payload could access readable local data, environment variables, browser or application credentials, and connected resources; modify files or user configuration; download additional payloads; or attempt persistence and privilege escalation. If the shell is elevated, the impact could extend to system-wide modification. The audited file does not prove that the current ins ...[truncated 121 chars]

Remediation
View remediation

Remediation Suggestions

Remove the irm ... | iex instruction. Replace it with a pinned and verifiable installation workflow:

  1. Download a version-specific PowerShell script or signed release artifact to disk.
  2. Validate its SHA-256 checksum against a trusted published value.
  3. Require a valid Authenticode signature from the expected publisher where supported.
  4. Review the downloaded script before executing it.
  5. Run it with standard-user privileges unless administrative access is strictly necessary.
  6. Prefer a reputable package manager with version pinning and signature validation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remotely fetched script without prior verification. If the distribution endpoint, TLS trust chain, or upstream release process is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description instructs the agent to use this skill for "ANY DialMyCalls request" and for any task that "involves DialMyCalls," which is an intentionally broad trigger that can overlap with many ordinary requests mentioning the service. It does not provide limiting conditions, exclusions, or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.