Back to skill

Security audit

Have I Been Pwned

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Have I Been Pwned lookups, but its setup instructions can execute remote installer scripts without verification or explicit approval.

Review this skill before installing if the oo CLI is not already present. Prefer installing the CLI from a verified, versioned source, and do not let an agent run the remote installer commands automatically without your approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions pipe a mutable network response directly into Bash. The downloaded installer is not pinned to a reviewed version, saved for inspection, or validated using a cryptographic signature or trusted checksum.

Consequently, the code executed when the instruction is followed can differ from the content available during this audit. HTTPS protects the connection in transit under normal conditions but does not establish that the current server-hosted payload is the same payload that was previously reviewed. Compromise of the distribution server, its deployment process, DNS or certificate trust, or the vendor account controlling the script could turn this installation instruction into an arbitrary-code execution channel.

Installing the required CLI may be legitimate when oo is absent, but directly piping remote content into a shell exceeds the minimum safe installation mechanism. The project does not include the installer, so its behavior and requested privileges cannot be verified from the audited artifact.

Attack Path

  1. The oo CLI is unavailable, causing an agent or user to consult the first-time setup section.
  2. An attacker compromises or gains control over https://cli.oomol.com/install.sh, or otherwise causes that endpoint to return a malicious script.
  3. The user or agent runs the documented command.
  4. curl retrieves the current response and pipes it directly to Bash without integrity or authenticity verification.
  5. Bash executes the attacker-controlled commands immediately.
  6. The payload can access resources available to the invoking account, modify user-writable files, install additional software, and initiate network c ...[truncated 668 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the pipe-to-shell installation command.
  • Direct users to a version-pinned release artifact from an authenticated release channel.
  • Download the artifact to disk before execution so that it can be inspected.
  • Publish a cryptographic checksum through a separately authenticated channel and verify it before installation.
  • Prefer signed packages and require verification of the publisher's signature.
  • Require explicit user approval before executing any installer.
  • Document the files, network destinations, and privileges used by the installer.
  • Avoid administrative execution unless a specific installation operation requires it.
  • If an installer script must be offered, use a workflow similar to:
bash
curl -fL -o install.sh "https://trusted.example/releases/vX.Y.Z/install.sh"
printf '%s  %s\n' 'PUBLISHED_SHA256' 'install.sh' | sha256sum --check
less install.sh
bash install.sh

The release URL and checksum must be version-specific and maintained through a trustworthy publication process.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 65
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup instruction uses Invoke-RestMethod (irm) to retrieve a mutable remote PowerShell script and pipes its contents directly into Invoke-Expression (iex). This executes the response as PowerShell code without saving it for review, pinning a release version, validating a checksum, or verifying a publisher signature.

The effective payload is controlled by the remote endpoint at execution time and can change after the Skill has been reviewed. HTTPS alone does not guarantee continuity between the audited behavior and the future content served by the endpoint. A compromised hosting environment, release pipeline, domain, certificate trust path, or vendor account could therefore transform the documented installer into an arbitrary-code execution mechanism.

Although installation of the CLI may be necessary when the command is missing, immediate evaluation of network-delivered text is not the least-privilege or minimum-risk way to perform that installation.

Attack Path

  1. The oo CLI is unavailable on a Windows system.
  2. An attacker causes https://cli.oomol.com/install.ps1 to serve attacker-controlled PowerShell.
  3. The user or agent follows the documented setup instruction.
  4. Invoke-RestMethod downloads the malicious response.
  5. Invoke-Expression immediately evaluates the response in the current PowerShell session.
  6. The payload executes commands with the current process token and can access or alter resources available to that account.

Impact Assessment

Exploitation results in arbitrary PowerShell execution with the invoking user's privileges. Potential scope includes reading user-accessible files and environment d ...[truncated 473 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex pattern.
  • Publish a version-pinned and Authenticode-signed installer or package.
  • Download the artifact to a local file before execution.
  • Validate both the publisher signature and a version-specific cryptographic checksum.
  • Let the user inspect the script and explicitly approve its execution.
  • Document whether elevation is needed and ensure installation runs without administrative rights whenever possible.
  • Prefer a trusted package manager or signed installer with fixed release metadata.
  • If a script remains necessary, use a staged process similar to:
powershell
Invoke-WebRequest -Uri "https://trusted.example/releases/vX.Y.Z/install.ps1" -OutFile ".\install.ps1"
if ((Get-FileHash ".\install.ps1" -Algorithm SHA256).Hash -ne "PUBLISHED_SHA256") {
    throw "Installer integrity verification failed"
}
Get-AuthenticodeSignature ".\install.ps1"
Get-Content ".\install.ps1"
.\install.ps1

Signature status must be validated programmatically before execution, and the release URL and checksum must be pinned to a specific reviewed version.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell, which executes unreviewed code from the network with the user's privileges. If the distribution endpoint, transport path, or hosted script is compromised, this becomes an immediate arbitrary code execution path on the local system.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Have I Been Pwned request" and "Whenever a task involves Have I Been Pwned," which is a broad activation condition without clear boundaries or exclusions. This can cause unintended invocation for casual mentions or adjacent tasks involving HIBP rather than a specific supported action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.