Back to skill

Security audit

Freshservice

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Freshservice use, but its fallback setup tells the agent to run unverified remote installer scripts, which deserves review before installation.

Before installing, review the oo CLI installation path yourself and avoid letting an agent run the curl-to-bash or irm-to-iex commands automatically. Use this skill only if you are comfortable sending Freshservice ticket data through the OOMOL connector, and confirm any ticket or service-request creation payload before it runs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60-64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions retrieve mutable scripts from an external server and execute them immediately using Bash or PowerShell. They do not pin a release, verify a cryptographic checksum or signature, or give the user an opportunity to inspect the downloaded content before execution.

Installing the oo CLI supports the Skill's declared Freshservice connector functionality, and the scripts are hosted on an OOMOL domain. However, direct pipe-to-shell execution exceeds the minimum necessary installation behavior because the same installation can be performed through a separately downloaded, authenticated, and explicitly approved artifact.

The effective code executed is not contained in the audited project and can change after review. Compromise of the installation server, hosting account, delivery infrastructure, or downloaded script could therefore turn the documented fallback installation procedure into arbitrary code execution.

Attack Path

  1. The oo command is unavailable, causing the Agent or user to follow the first-time installation instructions.
  2. An attacker compromises or gains the ability to alter the remote installation script or its delivery path.
  3. curl or PowerShell downloads the attacker-controlled script.
  4. The shell executes the response immediately without integrity or authenticity verification.
  5. The payload performs arbitrary actions using the invoking process's privileges.

Impact Assessment

Successful exploitation permits arbitrary command execution with the privileges of the user or Agent running the in ...[truncated 468 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace pipe-to-shell commands with installation through a trusted package manager or a version-pinned release artifact.
  2. Download the installer to a local file without executing it automatically.
  3. Publish and require verification of a cryptographic signature or checksum obtained through an authenticated channel.
  4. Pin the CLI version and immutable artifact URL so the reviewed payload cannot change silently.
  5. Display the artifact source, expected digest, requested privileges, and intended changes before installation.
  6. Require explicit user approval before executing any installer.
  7. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  8. Document that Freshservice action payloads and responses transit the OOMOL connector so users can make informed decisions about sending potentially sensitive ticket data.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote-code-execution risk: if the remote host, transport, installer, or distribution path is compromised, arbitrary code will execute immediately on the user's machine without verification.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Freshservice request" and "Whenever a task involves Freshservice," which is very broad and lacks boundaries or exclusion conditions. This can overlap with many ordinary references to Freshservice and may cause the skill to activate in contexts where the user did not intend to invoke it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.