Back to skill

Security audit

Gigasheet

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent read-only Gigasheet connector, but its setup instructions include unverified remote installer commands that can execute arbitrary code.

Review the setup path before installing. Prefer installing the oo CLI through a trusted, versioned, verifiable method rather than running the provided curl|bash or irm|iex commands, and only let the skill access Gigasheet when you intend it to inspect your connected account data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61-65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup instructions retrieve mutable scripts from cli.oomol.com and immediately execute them through Bash or PowerShell. They do not pin an installer version, verify a cryptographic checksum or publisher signature, save the script for inspection, or otherwise validate its integrity before execution.

HTTPS provides transport protection but does not establish that the remotely served script remains identical to the artifact that was reviewed. Compromise of the hosting origin, deployment pipeline, associated account, CDN, or another trusted delivery component could cause arbitrary replacement code to execute.

Installing the CLI may be relevant when it is unavailable, but direct execution of an unverified remote script is not the minimum privilege or safest mechanism required for the Skill's declared read-only Gigasheet operations. It also falls outside the Skill's declared Bash(oo *) runtime tool boundary.

Attack Path

  1. The oo CLI is unavailable and an authentication or connector action consequently fails.
  2. The user or agent follows the documented first-time setup instructions.
  3. The command downloads the current installer from the remote OOMOL endpoint.
  4. A compromised server or software-delivery path supplies attacker-controlled script content.
  5. The shell executes that content immediately without integrity verification or review.
  6. The payload performs arbitrary actions under the privileges of the user running the command and may retrieve additional payloads.

Impact Assessment

A substituted installer can obtain arbitrar ...[truncated 756 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash and irm | iex installation pipelines.
  • Prefer a trusted platform package manager and pin the CLI to a reviewed version.
  • If a standalone installer is required, download a versioned artifact to disk without executing it automatically.
  • Publish and verify a pinned SHA-256 checksum and a cryptographic publisher signature before execution.
  • Display the verified installer location and require explicit user approval before running it.
  • Keep dependency installation outside autonomous Skill execution and retain the declared Bash(oo *) least-privilege boundary.
  • Document the expected publisher identity, release source, version, checksum, and signature-verification procedure.
  • Fail closed if any integrity or authenticity check is unavailable or unsuccessful.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install the CLI via a direct network fetch piped into a shell (curl ... | bash), which executes remote code without prior verification. If the remote host, transport path, or install script is compromised, this becomes an immediate arbitrary code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for ANY Gigasheet request and whenever a task involves Gigasheet, which is an overly broad routing rule. That can cause the agent to invoke this skill on mere mentions of Gigasheet rather than on clear user intent, increasing the chance of unintended tool execution and unnecessary exposure of account metadata through connector calls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.