Back to skill

Security audit

Gladia

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Gladia through the OOMOL CLI, but its setup instructions can execute a mutable remote installer with the user's privileges.

Install only if you trust OOMOL's CLI distribution path and are comfortable using it for Gladia account operations. Before running the setup commands, prefer manually reviewing the official installer or using a pinned, verifiable package; confirm any write or delete action before letting the skill run it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Execution via Shell Pipeline

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from external URLs and immediately pass their contents to command interpreters. Neither installation path pins a release nor verifies a cryptographic signature or checksum before execution.

HTTPS provides transport protection but does not establish that the retrieved script is the same artifact that was reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, or upstream build process could alter the effective payload after this Skill has been audited.

The installation behavior supports the Skill's declared dependency on the oo CLI, but direct remote-to-shell execution exceeds the minimum privilege and trust necessary to install that dependency. A safer process can download a fixed release, authenticate it, and request explicit approval before execution.

Attack Path

  1. A Gladia action fails because the oo CLI is not installed.
  2. The user or agent follows the documented first-time setup instructions.
  3. The system retrieves the current contents of install.sh or install.ps1.
  4. The downloaded content is executed immediately without inspection or integrity verification.
  5. If the remote source or distribution chain has been compromised, attacker-controlled commands execute with the privileges of the invoking user.
  6. Those commands may access user-readable data, modify files, install additional software, or establish persistence, depending on host permissions and the installer execution context.

Impact Assessment

Successful exploitation pro ...[truncated 589 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove both direct execution pipelines (curl | bash and irm | iex).
  2. Direct users to an official package manager or a version-pinned release artifact.
  3. Download the installer or binary to a local file without executing it.
  4. Publish and verify a cryptographic signature from a separately distributed, trusted signing key. At minimum, verify a checksum pinned in the Skill to a specific release.
  5. Fail closed if signature or checksum validation does not succeed.
  6. Display the verified artifact path and request explicit user approval before execution.
  7. Avoid requiring administrator privileges unless a documented installation step strictly needs them.
  8. Document the exact version, expected publisher, destination paths, and filesystem or system changes made during installation.
  9. Apply equivalent integrity and approval controls to the macOS/Linux and Windows installation procedures.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software via a remote script piped directly into a shell, which executes unreviewed code fetched at runtime with the user's privileges. Because skill content is adversarial and the install command is presented as a remediation path, this creates a supply-chain and arbitrary code execution risk if the remote content is compromised, intercepted, or changed.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description uses sweeping activation language: "ANY Gladia request" and "Whenever a task involves Gladia," which is broader than a narrowly scoped trigger. This can cause unintended invocation because it does not define limits, exclusions, or negative examples for when the skill should not be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.