Back to skill

Security audit

ExpoFP

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for operating ExpoFP through OOMOL, but its setup instructions tell users to execute unverified remote installer scripts directly in a shell.

Review the oo CLI installation path before installing. Prefer an official package or manually download and verify the installer instead of running curl-to-bash or irm-to-iex directly. For normal ExpoFP use, confirm all write or delete payloads carefully before allowing the connector action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve installer scripts from external URLs and immediately pass their contents to bash or PowerShell's Invoke-Expression. The payload is not pinned to an immutable release and is not subjected to checksum, signature, or publisher verification before execution.

Although HTTPS protects the scripts while in transit, it does not prevent malicious execution if the distribution server, hosting account, DNS infrastructure, certificate issuance process, or published installer is compromised. It also does not ensure that the payload audited today is the payload served later. The downloaded scripts are absent from the project, so their behavior and required privileges cannot be independently reviewed.

This installation behavior exceeds the minimum privileges required for ordinary ExpoFP connector operations. Those operations only require an already installed oo CLI and commands matching oo connector ...; arbitrary remote shell execution is needed only for optional installation. The risk is partially reduced because the documentation says installation should occur only after an actual oo: command not found failure, but execution remains unverified.

Attack Path

  1. The oo CLI is unavailable and an agent or user follows the documented first-time setup.
  2. An attacker compromises or gains control over the installer endpoint or its delivery infrastructure.
  3. The endpoint serves a modified shell or PowerShell payload.
  4. curl | bash or irm | iex executes that payload immediately without local review or inte ...[truncated 1143 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove instructions that pipe network responses directly into a command interpreter.
  • Pin the CLI to a specific, reviewed release rather than a mutable installer URL.
  • Download the installer or binary to a local file without executing it automatically.
  • Verify a publisher signature or a cryptographic checksum obtained through an independently protected channel.
  • Prefer signed packages distributed through a trusted operating-system package manager.
  • Allow the user to inspect the downloaded artifact and require explicit approval before execution.
  • Run installation with ordinary user privileges unless a specific, documented step strictly requires elevation.
  • Document the files, network destinations, and system changes made by installation.
  • Keep installation outside the Skill's automated execution path; retain the existing requirement that setup only be offered after a genuine missing-command error.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software by piping a remote script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the server, transport, or referenced script is compromised, arbitrary code will run immediately on the user's machine without inspection.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY ExpoFP request," covering reading, creating, updating, and deleting data. That trigger scope is extremely broad and does not provide constraints or exclusion conditions, which could cause the skill to be invoked for loosely related ExpoFP mentions rather than clearly bounded tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.