Back to skill

Security audit

Formstack Documents

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Formstack Documents, but its first-time setup tells agents to execute remote installer scripts without integrity checks or clear user approval.

Review this skill before installing. Normal Formstack Documents connector use appears purpose-aligned, but do not let an agent run the installer snippets automatically; install the oo CLI only through a trusted, verifiable method you choose, and confirm all write or delete actions before they run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified macOS and Linux installer is piped directly into Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable shell script from an external URL and sends it directly to Bash. The project does not pin the installer to a specific version or verify a cryptographic signature or checksum before execution. Consequently, the code ultimately executed can change after this Skill has been reviewed.

The domain is consistent with the declared OOMOL provider, but domain consistency alone does not establish the integrity of every future response. A compromise of the hosting infrastructure, installer publication process, DNS or TLS trust chain could replace the expected installer with arbitrary shell commands.

This behavior exceeds the minimum privileges required for the Skill's declared connector functionality. The Skill can invoke an already-installed oo CLI without executing a remotely controlled installation script. Installation should remain a separate, user-controlled operation with verifiable artifacts.

Attack Path

  1. The oo command is unavailable, causing the user or Agent to consult the first-time setup instructions.
  2. An attacker compromises the remote installer, its publication infrastructure, or a relevant network trust dependency.
  3. curl retrieves the attacker-controlled response from the installer URL.
  4. The pipe passes the response directly to Bash without saving, reviewing, pinning, or validating it.
  5. Bash executes the supplied commands with the privileges of the invoking user.
  6. The payload can access data and resources available to that user and may attempt additional privilege escalation if the environment permits it.

Impact Assessment

Successful exploitation provide ...[truncated 576 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation instruction from the Skill.
  • Direct users to a version-pinned release artifact from the official distribution channel.
  • Require the artifact to be downloaded as a separate step rather than executed from a network stream.
  • Publish a cryptographic checksum or signature through an independently protected channel and verify it before execution.
  • Allow the user to inspect the downloaded installer before running it.
  • Prefer a trusted package manager with version pinning and package-signature validation where available.
  • Do not let the Agent install the CLI automatically; require an explicit, informed user decision.
  • Run installation with ordinary user privileges unless a narrowly defined operation demonstrably requires elevation.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified Windows installer is downloaded and executed through PowerShell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 65
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell instruction uses Invoke-RestMethod (irm) to retrieve a mutable script and pipes its contents to Invoke-Expression (iex). This executes the remote response as PowerShell code without version pinning, signature validation, checksum verification, or local review.

Although the URL belongs to the declared OOMOL service, the effective payload is not included in the audited project and may change after review. Compromise of the hosting system, release pipeline, DNS or TLS trust chain could therefore convert this setup command into an arbitrary code-execution channel.

Executing a remote installer is not required to perform the Skill's declared Formstack Documents operations when the oo CLI is already installed. Providing an immediate download-and-execute fallback therefore introduces privileges and supply-chain exposure beyond the minimum necessary for normal Skill operation.

Attack Path

  1. The oo command is unavailable on a Windows system.
  2. The user or Agent follows the first-time setup instruction.
  3. An attacker causes the installer endpoint to return malicious PowerShell code by compromising the relevant hosting, publication, or network trust infrastructure.
  4. irm retrieves the malicious response.
  5. The pipeline passes the response directly to iex, with no integrity check or review step.
  6. PowerShell executes the commands in the invoking user's security context.
  7. The payload can access, alter, or transmit resources available to that user.

Impact Assessment

Successful exploitation enables arbitrary PowerShell execution with the invoking user's privileges. Potential effects incl ...[truncated 493 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex instruction.
  • Provide a version-pinned installer or package from an official release location.
  • Download the installer to disk as a separate operation and require review before execution.
  • Sign the PowerShell script with a trusted code-signing certificate and validate the signature using Get-AuthenticodeSignature.
  • Publish and verify a cryptographic checksum through an independently protected channel.
  • Prefer a trusted Windows package manager that validates package provenance and supports explicit version selection.
  • Require explicit user authorization before installation and avoid automatic execution by the Agent.
  • Use a non-administrative PowerShell session unless a documented installation step strictly requires elevation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software via a remote script piped directly into a shell (curl ... | bash), which executes unverified code from the network without integrity checking. If the remote host, CDN, DNS, TLS trust chain, or distribution pipeline is compromised, this becomes an immediate arbitrary code execution path on the agent host.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description mandates using this skill for ANY Formstack Documents request and instead of calling the API directly, creating an overly broad trigger scope. This can cause the skill to be invoked in contexts where its guidance is not appropriate, increasing the chance of unintended execution paths, unsafe fallback behavior, or unnecessary exposure to write/destructive operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.