Back to skill

Security audit

Ipregistry

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Ipregistry lookups, but its fallback setup tells users or agents to execute a remotely downloaded installer directly, which needs review before installation.

Install only if you are comfortable using OOMOL's oo CLI for Ipregistry queries. Before running the first-time setup commands, prefer an official packaged or verifiable install path, inspect the installer, and avoid letting an agent run the remote installer automatically. Routine connector lookups appear purpose-aligned, but they will disclose the queried IP, ASN, or user-agent data to the connected service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installation Scripts Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

Both installation commands retrieve a mutable script from an external server and immediately execute it through a command interpreter. Neither command pins a release version nor verifies the payload using a cryptographic checksum or digital signature. The user or agent therefore cannot establish that the executed content is identical to the content reviewed when the Skill was published.

The instructions are conditional on the oo command being unavailable, rather than being part of every normal connector invocation. However, installing the CLI is ancillary setup, and executing an unverified remote payload grants substantially more local privilege than is required merely to query the Ipregistry service.

Although the URLs use HTTPS and refer to the declared OOMOL vendor domain, HTTPS alone does not protect against compromise of the hosting account, web server, DNS or certificate infrastructure, release pipeline, or vendor publishing credentials. If any of these are compromised, the remote script can be replaced without modifying the reviewed Skill.

The PowerShell form, irm ... | iex, has the same security properties as the shell form: remotely supplied text is evaluated directly as executable code without an integrity check or an opportunity for inspection.

Attack Path

  1. An attacker compromises the installation-script host, its deployment pipeline, publishing credentials, or another component capable ...[truncated 1723 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-interpreter installation commands from the Skill instructions.
  2. Direct users to an authenticated package manager or a version-pinned release artifact from the vendor's official release channel.
  3. Require the artifact to be downloaded to disk rather than executed directly:
    • Select an explicit, immutable version.
    • Download the installer and its independently published checksum or signature.
    • Verify a strong cryptographic checksum or vendor signature before execution.
    • Abort installation if verification fails.
  4. Publish signing keys through a separate trusted channel and document fingerprint verification and key-rotation procedures.
  5. Require explicit user approval before installing software or executing any downloaded installer. Do not let an agent initiate installation merely because a command is missing.
  6. Run installation with ordinary user privileges whenever possible. Avoid administrator or root execution unless a clearly documented installation step strictly requires it.
  7. Prefer platform-native, signed packages with pinned versions and reproducible release metadata.
  8. Document the files, directories, network endpoints, and privileges used by the CLI so users can evaluate the installation's scope.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI via a piped remote script (curl ... | bash), which executes code fetched at runtime without prior verification. If the install endpoint, TLS trust chain, DNS resolution, or distribution pipeline is compromised, this could lead to arbitrary code execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY Ipregistry request" and "Whenever a task involves Ipregistry," which is a very broad activation condition. It does not provide narrower trigger phrases, scope constraints, or negative examples to distinguish when this skill should or should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.