Back to skill

Security audit

GatherUp

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a read-only GatherUp connector skill, but its setup path includes unverified remote installer commands that deserve review before installation.

Review before installing. Use this skill only for the listed read operations unless the publisher documents additional actions. Do not let an agent automatically run the remote installer commands; install the oo CLI through a verified method or inspect and verify the installer first, and avoid elevated shells unless required.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions pipe mutable content retrieved from an external server directly into Bash or PowerShell. The downloaded scripts are executed without version pinning, cryptographic signature verification, checksum validation, or an opportunity to inspect the content locally.

Although the source domain is consistent with the declared OOMOL service and installation is only suggested when the oo command is unavailable, direct remote-script execution exceeds the minimum privilege and trust necessary to install a CLI. The effective executable payload can change after this Skill has been reviewed.

The behavior creates a supply-chain execution channel. A compromise of the installer host, publishing infrastructure, DNS resolution, or another relevant delivery component could cause arbitrary attacker-controlled commands to be returned and immediately executed.

Attack Path

  1. The oo CLI is not installed, causing an oo: command not found failure.
  2. The Agent or user follows the documented first-time setup instructions.
  3. The system requests install.sh or install.ps1 from cli.oomol.com.
  4. The external response is passed directly to Bash or PowerShell without integrity or authenticity verification beyond transport security.
  5. If the remote installer or its delivery infrastructure is compromised, attacker-controlled commands execute immediately.
  6. Those commands operate with the ...[truncated 870 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation patterns.

  2. Direct users to a versioned release artifact or an official package manager with package-signing support.

  3. Pin the CLI to a reviewed version rather than executing the latest mutable installer.

  4. Publish cryptographic hashes or signatures through a separately protected channel and require verification before execution.

  5. Download the installer to a local file first, verify its integrity and publisher, and permit inspection before running it.

  6. Require explicit user approval before installing software; the Agent should not automatically perform installation after a command failure.

  7. Run installation with ordinary user privileges whenever possible and clearly warn against using an elevated shell unless elevation is strictly required.

  8. Prefer instructions similar to:

    bash
    curl -fSLo oo-installer.sh "https://trusted.example/releases/VERSION/install.sh"
    echo "EXPECTED_SHA256  oo-installer.sh" | sha256sum --check
    less oo-installer.sh
    bash oo-installer.sh
    

    The real implementation must use an official versioned URL and a checksum or signature obtained from a trusted, independently protected source.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest promises a read-only skill for 'searching and reading data,' but the body introduces the possibility of write and destructive actions. That mismatch can cause downstream agents or users to trust the skill as non-mutating and invoke it in contexts where state changes are forbidden, creating a capability-confusion risk.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to execute a remote script directly via 'curl ... | bash', which is a classic supply-chain risk. If the hosting endpoint, CDN, DNS, or TLS trust chain is compromised, arbitrary code will run immediately on the user's machine without review.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase 'Use this skill for ANY GatherUp request' is overly broad and encourages automatic invocation for any mention of GatherUp, regardless of task sensitivity or whether the skill is appropriate. In agentic environments, broad routing rules can cause unintended tool use, expanding exposure to data access and any hidden connector capabilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document says all actions are listed below, but only read actions are actually enumerated while generic guidance for write/destructive actions is also present. This ambiguity obscures the true capability surface and can mislead an agent into assuming undocumented mutating actions may exist or are safe to infer dynamically from the connector schema.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.