Back to skill

Security audit

IP2Proxy

Security checks for vulnerabilities and agentic risk

Overview

This IP2Proxy skill is mostly coherent, but its first-time setup tells users to execute remote installer scripts directly, which is a high-impact install path without integrity checks.

Review this skill before installing. Normal IP2Proxy lookups through the oo CLI appear scoped and read-only, but do not run the documented remote installer commands unless you trust OOMOL's installer source and are comfortable with an unverified script changing your local environment. Prefer a pinned, signed, or checksum-verified installation path if available.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:55
Finding

Unverified Remote Shell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction retrieves a mutable shell script from an external server and immediately pipes it into Bash. The payload is not pinned to a specific release, saved for inspection, or verified using a cryptographic checksum or publisher signature.

HTTPS protects the payload in transit but does not protect users if the hosting service, deployment pipeline, DNS infrastructure, or publisher account is compromised. Because the remotely hosted script can change after this Skill has been reviewed, the command creates an external code-execution channel whose effective behavior cannot be determined from the audited package.

Installing the CLI may be relevant when it is absent, but immediate execution of unverified remote content exceeds the minimum privilege needed to provide installation guidance. A versioned and integrity-verified installation process would satisfy the same purpose without delegating arbitrary shell execution to a mutable URL.

Attack Path

  1. An action fails because the oo CLI is not installed.
  2. The user or agent follows the documented first-time setup instruction.
  3. curl downloads the current content of https://cli.oomol.com/install.sh.
  4. The downloaded bytes are passed directly to Bash without integrity verification or review.
  5. If the remote source or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the invoking account.
  6. Those commands can access user-readable data, alter files, install additional software, or establish persistence subject to the account's permissions.

Impact Assessment

Successful exploitation provides arbitrary command e ...[truncated 379 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation pattern.
  • Direct users to an official package manager or a versioned release artifact pinned to an explicit version.
  • Download the installer to a separate file rather than executing it as a stream.
  • Publish and verify a cryptographic signature or an independently distributed SHA-256 checksum before execution.
  • Display or inspect the verified script before running it.
  • Execute installation with ordinary user privileges and request elevation only for narrowly defined operations that require it.
  • Document the expected files, network destinations, and configuration changes made by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote PowerShell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This instruction uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script and sends the response directly to Invoke-Expression (iex). Invoke-Expression evaluates the downloaded text as PowerShell code without requiring the payload to be stored, reviewed, pinned, checksum-verified, or signature-validated.

The externally hosted script can be changed after the Skill package is audited. Compromise of the hosting service, release pipeline, DNS infrastructure, or publisher account would therefore permit substitution of the installer with arbitrary PowerShell commands. HTTPS alone does not establish that the current payload matches a reviewed release.

Although installing a missing CLI supports first-time setup, directly evaluating an unverified network response grants substantially broader capability than necessary.

Attack Path

  1. An action fails because the oo CLI is unavailable on Windows.
  2. The user or agent follows the documented PowerShell setup command.
  3. irm obtains the current response from https://cli.oomol.com/install.ps1.
  4. The response is piped directly into iex.
  5. A maliciously modified remote response executes as PowerShell code with the invoking process's privileges.
  6. The payload can access local files and credentials, change user configuration, download further components, or establish persistence within the permissions available to the account.

Impact Assessment

Successful exploitation enables arbitrary PowerShell execution as the invoking user. It may expose user-accessible secrets and files, permit modification of shell profiles or startup configuration, install additional paylo ...[truncated 143 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex pattern.
  • Prefer an official package manager or a versioned, signed release artifact.
  • Download the PowerShell installer to disk before considering execution.
  • Require validation through Authenticode or a securely published cryptographic checksum.
  • Pin documentation to an explicit installer version rather than a mutable endpoint.
  • Allow users to inspect the verified script and invoke it explicitly.
  • Run installation without administrator privileges unless a documented, narrowly scoped operation requires elevation.
  • Publish the installer's expected filesystem, registry, and network effects.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI via curl ... | bash, which executes a remote script directly without prior verification, pinning, or integrity checks. If the distribution endpoint, DNS, TLS trust chain, or hosting account is compromised, this becomes an immediate arbitrary code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use this skill for 'ANY IP2Proxy request' and 'Whenever a task involves IP2Proxy,' which is an expansive invocation rule that lacks boundaries or negative examples. In a markdown skill descriptor, this can cause unintended activation for loosely related mentions of IP2Proxy rather than clearly scoped requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.