Back to skill

Security audit

HubSpot

Security checks for vulnerabilities and agentic risk

Overview

This HubSpot skill is mostly purpose-aligned, but its setup instructions include unverified remote installer commands that can execute changing code on a user's machine.

Review the setup path before installing. The HubSpot actions and write confirmations are reasonably disclosed, but avoid running the remote installer pipelines unless you trust OOMOL's installer delivery path; prefer a versioned installer, documented checksum/signature verification, or official package manager flow where available.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:80
Finding

Unverified Remote Bash Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 80
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command pipes a remotely retrieved script directly into Bash. The payload is neither version-pinned nor verified using a cryptographic checksum or digital signature, and users have no opportunity to inspect it before execution. Consequently, the effective code can change after the Skill has been reviewed.

Installation of the oo CLI supports the declared HubSpot connector functionality, and the script is hosted on an OOMOL domain. Nevertheless, immediate execution of mutable network content is not the minimum safe installation mechanism. Compromise of the hosting service, its deployment process, or the network trust path could turn the documented setup procedure into arbitrary local code execution.

Attack Path

  1. The oo CLI is unavailable, causing an oo: command not found error.
  2. The agent or user follows the first-time setup instructions in SKILL.md.
  3. An attacker compromises or replaces the content served from https://cli.oomol.com/install.sh, or otherwise subverts the trusted delivery path.
  4. curl retrieves the attacker-controlled script.
  5. The shell pipeline passes the response directly to Bash without integrity verification or review.
  6. The payload executes with the privileges of the user running the command.

Impact Assessment

A malicious installer could run arbitrary commands with the invoking user's privileges. This may permit access to that user's files, environment variables, local application credentials, shell configuration, and accessible HubSpot-related data. It could also alter executables or configuration, download further payloads, or establish persistence where the user's permissions allow it. The instruction doe ...[truncated 205 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the pipe-to-shell installation method with a version-pinned package or downloadable release artifact.
  • Publish cryptographic checksums and signed release metadata through a separately authenticated channel.
  • Download the artifact to disk, verify its checksum and signature, and only then execute or install it.
  • Pin the installer or CLI to an audited version rather than retrieving mutable content from a generic installation URL.
  • Document the expected files, permissions, network connections, and configuration changes made by the installer.
  • Require explicit user approval before installation and do not let the agent perform unattended installation automatically.
  • Prefer the operating system's trusted package manager where supported.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:84
Finding

Unverified Remote PowerShell Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 84
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The command uses Invoke-RestMethod (irm) to retrieve a PowerShell script and pipes its response directly to Invoke-Expression (iex). This causes mutable network-delivered source code to execute immediately without version pinning, signature validation, checksum verification, or prior inspection.

Although installing the oo CLI is related to the Skill's declared functionality and the payload is hosted on an OOMOL domain, direct execution through iex exceeds the minimum safe mechanism needed to install a client. The audited Markdown file cannot guarantee what code the remote endpoint will serve later.

Attack Path

  1. The oo CLI is missing on a Windows system.
  2. The agent or user follows the PowerShell first-time setup instruction.
  3. An attacker compromises the remote installer, its publication pipeline, or another trusted part of the delivery path.
  4. irm downloads attacker-controlled PowerShell source.
  5. The pipeline forwards the response directly to iex, without validation or review.
  6. PowerShell executes the payload under the invoking user's security context.

Impact Assessment

Exploitation provides arbitrary PowerShell execution with the current user's privileges. A malicious payload could read or modify user-accessible files, collect environment variables and local credentials, change PowerShell profiles or application configuration, download additional components, and access resources available to the user. If the shell is already elevated, the payload would inherit those elevated privileges. No explicit elevation command is present in the documented instruction, so administrative access cannot otherwise be assumed.

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern.
  • Distribute a versioned installer or package with a documented SHA-256 digest and a verifiable publisher signature.
  • Save the installer locally before use, validate both its Authenticode signature and expected digest, and execute it only after successful verification.
  • Pin installation documentation to a reviewed release rather than a mutable generic script endpoint.
  • Clearly disclose the installer's filesystem, registry, environment, and network changes.
  • Require explicit user approval and avoid automatic installation by the agent.
  • Prefer a trusted Windows package-management channel when available.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via a remote shell pipeline (curl ... | bash), which executes network-fetched code without prior verification. If the hosting domain, transport path, or install script is compromised, arbitrary code could run on the user's machine; because this appears in a fallback setup path for a broadly-invoked skill, the exposure is materially more dangerous.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY HubSpot request" and "Whenever a task involves HubSpot," which is an extremely broad activation condition for a markdown/manifest file. It does not provide limiting conditions or negative examples, so ordinary mentions of HubSpot could be interpreted as a trigger for this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.