Back to skill

Security audit

folk

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Folk connector, but its first-time setup tells the agent to run unverified remote installer scripts, which is too risky for automatic skill instructions.

Review the installer path before installing. Prefer manually installing the OOMOL CLI from a trusted, versioned source with checksum or signature verification, and only connect the Folk account you intend this skill to manage. Confirm all write and delete actions carefully.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:69
Finding

Unverified Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 69–73
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from an external URL and execute them immediately using Bash or PowerShell. Neither command pins a release version, validates a cryptographic checksum or signature, nor saves the script for inspection before execution.

HTTPS protects the connection in transit under normal conditions, but it does not establish that the retrieved script is the same artifact that was reviewed. If the OOMOL domain, DNS configuration, certificate infrastructure, hosting environment, or installer publication process is compromised, the remote script can be replaced without modifying this skill package.

Installing the CLI may be necessary for the declared Folk integration, but direct pipe-to-shell execution is not the minimum privilege or minimum-risk installation mechanism necessary. Installation also occurs outside the restricted oo command surface declared by the skill and permits the downloaded payload to execute arbitrary commands with the invoking user's privileges.

The project does not contain the installer itself, so the installer's exact behavior cannot be verified from the audited artifact.

Attack Path

  1. The oo executable is unavailable, causing an oo: command not found error.
  2. The user or agent follows the documented first-time setup procedure.
  3. Bash retrieves install.sh through curl, or PowerShell retrieves install.ps1 through Invoke-RestMethod.
  4. The downloaded response is passed directly to a command interpreter without integrity or authenticity verification beyond HTTPS.
  5. A compromised or malicio ...[truncated 1018 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct pipe-to-shell installation commands from agent-executable instructions.
  2. Direct users to a version-pinned release hosted through an official, auditable distribution channel.
  3. Download the installer or package to a local file without executing it immediately.
  4. Publish SHA-256 or stronger checksums through a separately protected channel and require verification before execution.
  5. Prefer signed packages and verify the publisher's cryptographic signature using a pinned, trusted public key.
  6. Display the resolved artifact version, source URL, checksum, and intended changes before requesting explicit user approval.
  7. Run installation with ordinary user privileges and avoid automatic elevation. If elevated access is genuinely necessary, document each privileged operation and request approval separately.
  8. Keep dependency installation outside autonomous skill execution. The skill should fail safely and provide manual installation guidance rather than execute remotely retrieved code.
  9. Pin the CLI version used by the skill and define a controlled, separately reviewed upgrade process.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network without integrity checks, version pinning, or manual review; if the remote host, CDN, or connection path is compromised, arbitrary code execution can occur on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

For manifest/markdown content, trigger guidance should be specific enough to avoid unintended invocation. The phrase 'ANY folk request' is intentionally broad and does not provide exclusion conditions or scope constraints beyond mentioning Folk, increasing the chance the skill is invoked in situations where a more precise trigger policy would be safer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.