Back to skill

Security audit

Formbricks

Security checks for vulnerabilities and agentic risk

Overview

This Formbricks skill is mostly purpose-aligned, but its first-time setup tells agents to run unverified remote installer scripts directly, which warrants user review before installation.

Review the first-time setup carefully before installing. Prefer installing the oo CLI through a trusted, version-pinned, verifiable method, and confirm all Formbricks write or destructive actions before allowing the agent to run them.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installation Scripts Are Downloaded and Immediately Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61-65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions download mutable scripts from an external server and pass them directly to a command interpreter. Neither command pins a release version, verifies a cryptographic signature or checksum, nor saves the script for inspection before execution.

HTTPS protects the connection in transit but does not guarantee that the hosted payload is immutable or safe. If the download server, hosting account, DNS infrastructure, certificate issuance process, or release pipeline is compromised, the delivered script can be replaced after this Skill has been reviewed. The effective code executed by the user is therefore outside the audited project.

This installation mechanism is not required for routine Formbricks operations when the oo CLI is already installed. Although the instructions limit it to first-time setup after an oo: command not found error, arbitrary remote-script execution exceeds the minimum privileges required merely to install a known CLI artifact safely.

Attack Path

  1. The user or Agent attempts to invoke oo and receives an oo: command not found error.
  2. The Agent follows the documented first-time setup procedure.
  3. The shell retrieves the current contents of install.sh or install.ps1 from the external OOMOL host.
  4. The response is immediately interpreted by Bash or PowerShell without integrity verification or review.
  5. An attacker controlling or compromising the delivery infrastructure substitutes malicious script content.
  6. The substituted payload executes with the permissions of the user who launch ...[truncated 712 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex installation patterns.
  2. Direct users to a version-pinned release artifact hosted in the official release repository.
  3. Download the artifact to a local file without automatically executing it.
  4. Publish and require verification of a cryptographic signature or a trusted, version-specific SHA-256 checksum before installation.
  5. Execute the verified local installer only after verification succeeds.
  6. Prefer signed operating-system package repositories or platform-native package managers where available.
  7. Apply equivalent integrity controls to both the Bash and PowerShell installation paths.
  8. Document the files, permissions, and network endpoints used by the installer so users can assess the installation scope.
  9. Avoid requesting elevated privileges unless a specific installation step strictly requires them, and explain any such requirement before execution.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software via curl ... | bash, which executes a remote script directly without verification. If the distribution server, DNS, TLS trust chain, or hosted script is compromised, arbitrary code could run on the host with the user's privileges, making this especially dangerous in an agent skill that may be followed automatically during setup failure handling.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase "Use this skill for ANY Formbricks request" and "Whenever a task involves Formbricks, use this skill" is extremely broad and lacks constraints or negative examples. In a manifest/markdown context, this can cause unintended invocation for loosely related mentions of Formbricks rather than clearly scoped operational requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.