Back to skill

Security audit

Headout

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent read-oriented Headout connector, but its fallback setup tells users or agents to run unverified remote installer scripts with shell execution.

Review before installing. The Headout read actions are coherent, but do not run the documented curl|bash or irm|iex installer unless you trust OOMOL's installer endpoint and understand it can execute local code. Prefer an official signed or checksum-verified installation method for the oo CLI, and require confirmation before any unlisted, write, or destructive Headout action is run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Shell Script Execution via curl and Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable script from an external URL and passes the response directly to Bash. It does not pin an installer version, verify a cryptographic signature or checksum, save the script for inspection, or constrain the commands that the script may execute.

HTTPS protects the connection in transit under normal conditions, but it does not establish that every future script served by the endpoint is the same script reviewed during this audit. The effective payload remains outside the audited project and may change at any time. Compromise of the hosting infrastructure, publishing account, domain, or installer distribution process would allow arbitrary commands to be supplied to users following this instruction.

Installing the required CLI supports the Skill's functionality, but immediate execution of an unverified network response exceeds the minimum safe privilege necessary. A pinned and authenticated installation mechanism could provide the same functionality with lower risk.

Attack Path

  1. The oo CLI is absent, causing an oo: command not found failure.
  2. The agent or user follows the fallback installation instruction in SKILL.md.
  3. The command retrieves the current response from https://cli.oomol.com/install.sh.
  4. The response is passed directly to Bash without integrity verification or review.
  5. If the remote endpoint or release process has been compromised, attacker-controlled shell commands execute with the privileges of the invoking user.
  6. Those commands may access local files and credentials, modify user-level configuration, establish persistence, or retrieve additional payloads, subject to the invoking account's pe ...[truncated 542 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Prefer a signed platform package manager or a pinned release artifact from an authenticated release channel.
  • Pin an exact CLI version rather than retrieving a mutable latest installer.
  • Download the artifact to disk before execution and verify a publisher signature and documented SHA-256 checksum.
  • Fail closed when verification does not succeed.
  • Present the source, version, expected permissions, filesystem changes, and network behavior to the user before installation.
  • Require explicit user approval before executing any installer.
  • Run installation with the least-privileged account possible and avoid requesting administrator privileges unless strictly required.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Unverified Remote PowerShell Script Execution via Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This instruction uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script and pipes its contents directly into Invoke-Expression (iex). Invoke-Expression interprets the downloaded response as PowerShell code immediately, without version pinning, signature validation, checksum verification, local inspection, or execution constraints.

The payload resides outside the audited project and can be changed after review. Although the endpoint uses HTTPS and an OOMOL-branded domain, those properties do not protect against compromise of the publisher, hosting environment, domain, or release pipeline. Any attacker able to alter the endpoint's response can execute arbitrary PowerShell commands on systems that follow the instruction.

Installing the CLI is relevant to the declared Headout connector workflow, but evaluating an unverified remote response is not the least-privileged installation method.

Attack Path

  1. The oo CLI is unavailable on a Windows host.
  2. The agent or user follows the documented PowerShell fallback.
  3. Invoke-RestMethod downloads the current contents of https://cli.oomol.com/install.ps1.
  4. The pipeline sends that content directly to Invoke-Expression.
  5. A compromised endpoint or publishing process supplies attacker-controlled PowerShell.
  6. PowerShell executes the payload with the invoking process's privileges.
  7. The payload may read accessible files and credentials, alter user configuration, create persistence mechanisms, or download further components.

Impact Assessment

Successful exploitation yields arbitrary PowerShell execution in the security context of the invoking user. The attacker can access ...[truncated 388 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Distribute the CLI through a signed Windows package or a pinned release artifact.
  • Apply Authenticode signing and verify that the signature chains to an expected publisher before execution.
  • Publish and verify a cryptographic checksum over the exact installer version.
  • Download the installer to a local file so its origin, signature, and contents can be inspected before execution.
  • Require explicit user approval after displaying the pinned version, publisher, permissions, and expected changes.
  • Avoid elevated PowerShell unless installation genuinely requires it, and document any required privileges.
  • Configure the installation process to fail closed if publisher or integrity verification fails.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via 'curl ... | bash', which executes a remote script directly without verification. If the hosting endpoint, transport, or distribution pipeline is compromised, this becomes a straightforward remote code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest promises a skill for 'searching and reading data,' but the instructions tell the agent to inspect live connector schemas and run arbitrary actions by name. That creates a scope gap where newly added or undocumented write-capable actions could be invoked despite the skill being presented as read-oriented, increasing the chance of unintended state-changing operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Headout request," which is a very broad activation condition without constraints or exclusions. This can overlap with many ordinary requests that merely mention Headout and may cause unintended invocation instead of more context-appropriate handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructs the agent to discover the connector's live schema and execute actions based on that dynamic surface, while the safety section assumes untagged actions are safe reads. If the live connector exposes additional actions not listed here, the agent may treat them as safe without human review, undermining the safety model.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.