Back to skill

Security audit

Hyperbrowser

Security checks for vulnerabilities and agentic risk

Overview

The Hyperbrowser skill is mostly coherent, but its fallback setup tells the agent to run unverified remote installer scripts, which is high-impact local code execution.

Review this skill before installing. The Hyperbrowser connector behavior is understandable, but do not let an agent run the documented installer commands automatically; install the oo CLI only through a verified, user-initiated process with trusted release provenance.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Shell Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions pipe a remotely retrieved installation script directly into bash. The content is executed without being displayed, reviewed, pinned to a specific release, or verified using a cryptographic signature or trusted checksum.

Although installation is presented as a fallback for a missing oo CLI rather than an automatic step, direct execution of mutable remote content creates a time-of-check/time-of-use supply-chain boundary: the script delivered during installation may differ from the content assessed when this Skill was reviewed. HTTPS protects the connection in transit but does not protect against compromise of the hosting service, publishing account, build pipeline, DNS/control plane, or upstream installation artifacts.

Installing the CLI is ancillary setup rather than part of the Skill's declared Hyperbrowser operations. Executing an unrestricted remote shell script therefore exceeds the privileges required to run the documented oo connector schema and oo connector run commands.

Attack Path

  1. The oo executable is absent, causing a command-not-found failure.
  2. The Agent or user follows the documented first-time installation fallback.
  3. An attacker compromises the remote script, its publishing pipeline, or the infrastructure serving it.
  4. curl retrieves the attacker-controlled response.
  5. The pipe passes the response directly to bash without inspection or integrity validation.
  6. The payload executes with the privileges of the Agent or user running the command.

Impact Assessment

A malicious installer can execute arbitrary shell commands with the invoking account's privileges. Depending on that a ...[truncated 464 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe network responses directly into a shell.
  • Link to a documented, manually initiated installation process rather than instructing the Agent to execute the installer.
  • Pin the CLI to an explicit release version hosted on a trusted release channel.
  • Download the installer or package to a local file first.
  • Verify a publisher signature and a cryptographic checksum obtained through an independently authenticated channel.
  • Inspect the verified artifact before executing it as a separate command.
  • Request explicit user approval before performing software installation or privilege elevation.
  • Prefer a signed operating-system package with narrowly scoped permissions and documented provenance.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote PowerShell Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup instruction retrieves mutable PowerShell content with Invoke-RestMethod (irm) and immediately evaluates it with Invoke-Expression (iex). There is no version pinning, local inspection, Authenticode validation, or cryptographic checksum verification between retrieval and execution.

Invoke-Expression treats the complete network response as PowerShell source code. Consequently, compromise of the hosting or publication chain becomes arbitrary local code execution. HTTPS alone does not establish the integrity or provenance of the script publisher and cannot prevent a compromised server from returning a malicious payload.

This installation behavior is not required for individual Hyperbrowser connector operations and grants remote content a broader code-execution capability than the declared functionality requires.

Attack Path

  1. The oo executable is unavailable on a Windows system.
  2. The Agent or user follows the PowerShell fallback instruction.
  3. An attacker gains control over the installation script or its delivery infrastructure.
  4. irm downloads the modified PowerShell response.
  5. The pipeline forwards the response directly to iex.
  6. PowerShell executes the attacker-controlled code in the invoking user's security context.

Impact Assessment

Successful exploitation provides arbitrary PowerShell execution with the privileges of the invoking process. The payload could access files and credentials available to that account, modify user or system configuration, download additional programs, establish persistence, replace trusted tools, or exfiltrate accessible data. Administrative impact is possible if t ...[truncated 224 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex pattern.
  • Use a signed, version-pinned release package from a verified publisher.
  • Save the artifact locally before execution.
  • Validate its Authenticode signature and a published cryptographic checksum.
  • Reject unsigned artifacts, signature failures, checksum mismatches, redirects to unapproved origins, and unexpected content types.
  • Execute the verified artifact separately without Invoke-Expression.
  • Require explicit user consent before installation or elevation.
  • Document the expected files, permissions, network destinations, and uninstall procedure.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs the agent to install the CLI by piping a remotely fetched script directly into bash, which is a well-known unsafe pattern because any compromise of the remote host, CDN, TLS trust chain, or install script immediately becomes arbitrary code execution. In this skill context, the risk is elevated because the agent may execute shell commands on behalf of the user, so a fallback troubleshooting step can turn into full local system compromise rather than a merely informational documentation issue.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Static analysis

No suspicious patterns detected.