Back to skill

Security audit

IPQualityScore

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for IPQualityScore access, but its first-time setup tells the agent to run unverified remote installer scripts.

Install only if you are comfortable using OOMOL as the broker for IPQualityScore requests. Do not let an agent run the remote installer commands automatically; install the oo CLI from a trusted, verified source and review any setup command before execution.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions retrieve mutable scripts from https://cli.oomol.com and immediately execute their contents using Bash or PowerShell. No fixed version, cryptographic signature, checksum, or independent verification is required before execution.

HTTPS protects the connection in transit under normal conditions, but it does not establish that the remotely hosted script is immutable or safe. Compromise of the distribution server, its deployment process, DNS or certificate infrastructure, or an authorized publishing account could cause arbitrary attacker-controlled commands to be returned and executed. The effective installation payload can also change after the Skill has been reviewed.

Installing the required CLI is related to the Skill's declared functionality, but direct pipe-to-shell execution exceeds the minimum privilege and trust necessary to perform that installation. A downloaded artifact can instead be pinned and authenticated before the user separately executes it.

Attack Path

  1. The oo CLI is absent, causing the Skill's first-time setup instructions to become applicable.
  2. An attacker compromises or otherwise gains control over the remote installation response delivered by cli.oomol.com.
  3. The user or Agent runs the documented curl | bash or irm | iex command.
  4. The shell interprets the response immediately, without giving the user an opportunity to inspect or authenticate it.
  5. The malicious script executes arbitrary commands with the privileges of the user running the installation command.
  6. The pa ...[truncated 986 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation commands from the Skill instructions.
  2. Direct users to a documented official package manager or a versioned release artifact hosted in an authoritative repository.
  3. Pin the CLI to a specific reviewed version rather than retrieving an unversioned installation script.
  4. Publish a SHA-256 checksum or, preferably, a cryptographic signature for every release artifact.
  5. Require users to download the artifact to disk, verify its signature or checksum, and execute it as a separate step.
  6. Provide platform-specific instructions that avoid unnecessary administrative privileges.
  7. If an installer script must be distributed, make its source auditable, pin its exact version or commit, authenticate it before execution, and clearly display the commands users are expected to run.
  8. Keep the existing behavior of attempting normal connector operations before presenting setup steps, so installation is not triggered unless the CLI is actually unavailable.

A safer high-level workflow is:

text
Download a specific release artifact
→ verify its publisher signature and pinned checksum
→ inspect or install the verified artifact separately
→ run the CLI without elevated privileges unless explicitly required
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software using a remote-script pipe-to-shell pattern (curl ... | bash), which executes code fetched over the network without prior verification. In an adversarial or compromised distribution scenario, this can lead to arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY IPQualityScore request" and "Whenever a task involves IPQualityScore," which is a very broad activation condition for a markdown/manifest-style skill description. It does not provide constraints or negative examples to distinguish when the skill should or should not activate, increasing the chance of collisions with general discussion or indirect references to the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.