Back to skill

Security audit

Eventzilla

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for read-only Eventzilla access, but its setup instructions tell users to execute remote installer scripts without pinning or verification.

Review the installer path before installing. Prefer using OOMOL's official, versioned installation guidance or a package manager, and avoid running the curl-to-bash or irm-to-iex commands unless you trust the endpoint and understand they execute remote code on your machine. For normal use, the skill appears intended for read-only Eventzilla access through the oo connector.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60-68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

The first-time setup instructions execute remotely hosted installation scripts directly in a shell:

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

Both installation commands combine remote retrieval with immediate code execution. The downloaded scripts are not version-pinned, inspected, hash-verified, or authenticated using a detached signature. Consequently, the code ultimately executed can change after the Skill has been reviewed.

Although the scripts are hosted on an OOMOL domain and installation is presented only as a fallback when the oo command is unavailable, domain ownership alone does not establish the integrity of each downloaded payload. Compromise of the hosting infrastructure, deployment pipeline, domain, or trusted endpoint could cause arbitrary attacker-controlled commands to run. The curl -fsSL options affect transfer behavior but do not verify the script against a known-good artifact. The PowerShell irm ... | iex instruction has the equivalent weakness.

Installing the CLI may support the declared Eventzilla connector functionality, but immediate execution of a mutable network response exceeds the minimum privilege necessary. A verified, version-pinned installation mechanism can provide the same functionality without piping an unreviewed response directly into an interpreter.

Attack Path

  1. The oo CLI is absent, and an operator or agent follows the documented fallback setup.
  2. An attacker compromises the remote installer endpoint, its publishin ...[truncated 1144 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-interpreter installation commands from the Skill instructions.
  2. Direct users to a version-pinned package or release artifact obtained through an authenticated package manager or official release channel.
  3. If a standalone installer is necessary, download it to a local file without executing it:
    • Use a fixed versioned URL.
    • Publish a trusted SHA-256 digest and verify it before execution.
    • Prefer a detached cryptographic signature whose verification key is distributed through a separate trusted channel.
    • Abort installation if any integrity or signature check fails.
  4. Allow the user to inspect the downloaded installer and require explicit approval before executing it.
  5. Run installation with ordinary user privileges unless elevated access is demonstrably required. Do not embed automatic privilege elevation in the installer flow.
  6. Document the files, configuration changes, and network endpoints used by the installer.
  7. For automated environments, fail with a clear manual installation message instead of automatically retrieving and executing remote code.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via a remote shell pipeline (curl ... | bash), which executes code fetched over the network without independent verification. If the install endpoint, transport, DNS, or hosting is compromised, this can lead to arbitrary code execution on the user's machine; embedding it in a troubleshooting section makes accidental execution more likely.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Eventzilla request" and "Whenever a task involves Eventzilla," which is an expansive activation condition without examples or exclusions. This is broad enough to match many routine mentions of Eventzilla, making invocation scope unclear.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.