Back to skill

Security audit

Fillout

Security checks for vulnerabilities and agentic risk

Overview

This Fillout skill is mostly coherent, but its setup instructions tell users to execute mutable remote installer scripts directly, which is high-impact enough to require review.

Install only if you trust OOMOL's CLI distribution path and are comfortable with the Fillout account access this connector will have. Prefer manually downloading and verifying the oo CLI from official documentation instead of piping installer scripts directly into a shell, and confirm any create or delete action before it runs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Executed Directly Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command downloads a mutable shell script from an external URL and pipes it directly into Bash. The remote content is executed without version pinning, checksum validation, digital-signature verification, local inspection, or a separate confirmation step.

Although this instruction is presented as first-time setup and uses the CLI vendor's domain, the effective code is not contained in the reviewed project. It can change after the skill has been audited. Compromise of the hosting service, release process, domain, or applicable TLS trust chain could therefore turn the documented installation step into arbitrary local code execution.

Installing the CLI may be necessary for the declared Fillout integration, but immediate execution of an unverified remote script exceeds the minimum privilege and trust required to distribute that CLI.

Attack Path

  1. The oo command is unavailable, causing the user or agent to consult the first-time setup instructions.
  2. An attacker compromises or modifies the remote installer, its hosting infrastructure, release pipeline, domain resolution, or another relevant delivery component.
  3. The user executes the documented curl ... | bash command.
  4. curl retrieves the attacker-controlled script and sends it directly to Bash without an opportunity for review or integrity verification.
  5. Bash executes the payload with all privileges available to the invoking account.

Impact Assessment

A malicious installer can execute arbitrary commands with the invoking user's privileges. It could access or modify user-readable files, steal locally accessible credentials or session data, install additional ...[truncated 434 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe downloaded content directly into a shell.
  • Publish versioned CLI artifacts through a trusted package manager or a version-pinned release URL.
  • Download the artifact to a local file before execution.
  • Publish a cryptographic checksum and preferably a signature through an independently protected channel.
  • Verify the checksum and signature before running the installer.
  • Display the resolved version and source to the user and require an explicit installation decision.
  • Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  • Document the files, permissions, network destinations, and persistent changes made by the installer.
  • Prefer a sequence such as download, verification, inspection, and separate execution rather than a single pipeline.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Unverified Remote Installer Executed Directly Through PowerShell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

Invoke-RestMethod (irm) retrieves a mutable PowerShell script from an external server and passes it directly to Invoke-Expression (iex). PowerShell interprets the response as executable code without pinning a release, validating a checksum or signature, saving it for inspection, or separating retrieval from execution.

The vendor-associated HTTPS domain provides transport protection but does not establish that future content at the URL will match the content intended during this audit. A compromised server, publishing pipeline, domain, or trusted delivery component could substitute arbitrary PowerShell commands.

Installing the required CLI is related to the skill's functionality, but dynamically evaluating unverified network content grants substantially more trust and execution capability than is necessary.

Attack Path

  1. The oo CLI is absent on a Windows system.
  2. The user follows the documented first-time installation instruction.
  3. An attacker has caused the remote install.ps1 response to contain malicious PowerShell.
  4. irm downloads the response into the pipeline.
  5. iex immediately evaluates the response in the current PowerShell session.
  6. The payload executes with the permissions and environmental access of that session.

Impact Assessment

Successful exploitation provides arbitrary PowerShell execution under the invoking account. The payload could read or alter accessible files, collect environment or authentication data, execute additional programs, download further payloads, modify user configuration, establish persistence, and communicate with external systems. Running the instruction from an ...[truncated 295 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern.
  • Distribute a versioned and Authenticode-signed PowerShell script, MSI, or package-manager artifact.
  • Download the artifact without executing it and verify its expected publisher signature and cryptographic digest.
  • Fail closed if signature, publisher, version, or checksum validation does not succeed.
  • Require a separate, explicit command to execute the verified artifact.
  • Avoid administrative execution unless installation genuinely requires it; clearly identify any operation requiring elevation.
  • Document installer behavior, including filesystem changes, registry changes, persistence mechanisms, and outbound connections.
  • Pin documentation to a specific release while providing a controlled and authenticated update process.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill includes a curl ... | bash installation command that fetches and executes a remote script directly from the network. If the remote host, transport path, or script content is compromised, this can result in arbitrary code execution on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for 'ANY Fillout request' and 'Whenever a task involves Fillout,' which is an extremely broad trigger for a markdown skill description. It does not provide boundaries, exclusions, or negative examples, so ordinary mentions of Fillout-related tasks could match unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.