Back to skill

Security audit

Hacker News

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Hacker News connector, but its first-time setup tells users to run unverified remote installer scripts directly in a shell.

Review the first-time setup before installing. Prefer installing the oo CLI through a trusted, verifiable method with version pinning or checksum/signature verification, and do not let an agent run the remote installer automatically just because oo is missing. The normal Hacker News read/search actions appear coherent once the CLI is already installed and signed in.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:68
Finding

Unverified Remote Installer Retrieval and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 68–72
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from an external server and immediately execute them using Bash or PowerShell. Neither command pins a specific artifact version, verifies a cryptographic checksum or digital signature, nor gives the user an opportunity to inspect the downloaded script before execution.

HTTPS protects the network connection under normal conditions, but it does not establish that the current contents of a mutable installer are identical to those reviewed during this audit. Compromise of the distribution server, hosting account, DNS infrastructure, CDN, TLS signing chain, or installer publishing process could replace the script with arbitrary commands.

The installation operation also exceeds the minimum privileges needed for the Skill's declared Hacker News reading and searching functionality. Hacker News exposes public data, while installing and executing a third-party CLI introduces a general-purpose local code-execution channel. Although the instructions state that installation should only occur after a missing-command failure, this condition does not mitigate the integrity risk of the downloaded installer.

Attack Path

  1. The oo command is unavailable when the Skill is used.
  2. The operator or agent follows the documented first-time setup fallback.
  3. An attacker compromises or gains control over the remotely hosted installer or its delivery infrastructure.
  4. The attacker modifies install.sh or install.ps1 to contain malicious commands.
  5. curl | bash or irm | iex passes the response directl ...[truncated 814 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all pipe-to-shell installation instructions, including both curl | bash and irm | iex.
  2. Distribute the CLI through a trusted package manager or provide a version-pinned installer artifact.
  3. Publish a cryptographic checksum and, preferably, a verifiable digital signature for every installer release.
  4. Require users to download the artifact separately, verify its signature or checksum, inspect it when appropriate, and then execute it as an independent step.
  5. Require explicit user approval before installing software; an agent should never initiate installation automatically merely because a command is missing.
  6. Document the exact installer version, expected publisher, requested permissions, installation destination, and files or services that will be modified.
  7. Run installation with standard-user privileges wherever possible and request elevation only for a narrowly defined operation that genuinely requires it.
  8. Consider using Hacker News's public interfaces directly for read-only functionality, avoiding installation of a general-purpose intermediary CLI when it is not essential.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into a shell, which is a classic supply-chain and remote-code-execution risk. If the install endpoint, CDN path, DNS, TLS trust chain, or hosting account is compromised, the agent could execute arbitrary attacker-controlled code on the host.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill for "ANY Hacker News request" and "Whenever a task involves Hacker News," which is a broad activation condition rather than a narrowly defined trigger. It does not provide exclusions or negative examples, so ordinary references to Hacker News could be interpreted as invoking this skill unnecessarily.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.