Back to skill

Security audit

Habitica

Security checks for vulnerabilities and agentic risk

Overview

The Habitica skill is mostly purpose-aligned, but its first-time setup tells users to execute remote installer scripts directly, which should be reviewed before installation.

Review the oo CLI installation path before using this skill. Prefer an official, version-pinned installer or package manager flow with checksum or signature verification instead of running the provided pipe-to-shell commands. For normal Habitica use, confirm any write or delete action payload before allowing it to run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 65–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from cli.oomol.com and immediately pass their contents to Bash or PowerShell. The downloaded payload is not displayed for review, pinned to a specific version, checked against a cryptographic digest, or authenticated with a verifiable signature.

Consequently, the code that executes can differ from the content available when this Skill was audited. Compromise of the download server, hosting infrastructure, publishing credentials, DNS resolution, TLS termination, or release process could turn these installation commands into an arbitrary-code-execution channel.

Installing the oo CLI is ancillary setup rather than part of the Skill's routine Habitica functionality. Automatic execution of a mutable installer therefore exceeds the minimum privileges needed to issue the documented connector commands. Although the instructions only recommend installation after an oo: command not found failure, they still expose any user or agent following that fallback to the remote payload.

No evidence in the reviewed file establishes that the current remote scripts are malicious, and the package contains no local executable scripts. The vulnerability arises from trusting and executing future remote content without independent verification.

Attack Path

  1. An attacker compromises the installer host, publishing process, DNS path, or another component capable of changing the response from https://cli.oomol.com/install.sh or install.ps1.
  2. The oo command is unavailable, causing the documented first-time setup condition to occur. ...[truncated 1204 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-interpreter installation commands.
  2. Direct users to a documented manual installation flow or a trusted platform package manager.
  3. Pin the CLI to an explicit release version rather than downloading a mutable installer endpoint.
  4. Download the artifact without executing it, then verify a publisher-signed release and a checksum obtained through an independently authenticated channel.
  5. Display the verified script or package source and require explicit user approval before installation.
  6. Run installation with ordinary user privileges whenever possible; do not request administrator or root access unless a specific installation step requires it.
  7. Publish reproducible release artifacts and document the expected signing identity, checksum format, and verification commands.
  8. Keep CLI installation outside automated Skill execution. If the CLI is missing, report the prerequisite and allow the user to choose whether and how to install it.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network without integrity checking, so a compromised server, CDN, DNS path, or upstream script could lead to arbitrary code execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Habitica request" and "Whenever a task involves Habitica, use this skill," which is a very broad activation condition. It does not provide boundaries, exclusions, or negative examples to clarify when the skill should not activate, increasing the chance of collisions with ordinary discussion about Habitica.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.