Back to skill

Security audit

Klazify

Security checks for vulnerabilities and agentic risk

Overview

The skill's Klazify querying behavior is coherent, but its setup instructions include unverified remote installer scripts that would run in a local shell.

Install this only if you trust OOMOL and need Klazify access through the oo CLI. Prefer an already installed or organization-approved oo CLI, and do not let an agent run the curl-to-bash or PowerShell iex installer automatically; use a verified installer, avoid elevated shells, and review any login, connection, or billing step before proceeding.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installation Scripts Executed Directly by System Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62–66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup documentation downloads mutable scripts from cli.oomol.com and immediately passes their contents to bash or PowerShell for execution. There is no pinned script version, expected cryptographic hash, digital-signature validation, or opportunity to inspect the downloaded content before execution.

HTTPS protects the connection in transit under normal conditions, but it does not ensure that the server-hosted script remains identical to the version intended when the Skill was reviewed. Compromise of the installation endpoint, its deployment pipeline, the hosting account, or the trusted delivery infrastructure could therefore replace the installer with arbitrary commands.

Installing the oo CLI is relevant to the declared functionality, but directly executing an unverified network response exceeds the minimum mechanism necessary to perform that installation. A separately downloaded, version-pinned, and cryptographically verified artifact would provide the required functionality with substantially lower risk.

No evidence establishes that the currently hosted scripts contain malicious code. The vulnerability arises because the effective code is remote, mutable, and executed without local verification.

Attack Path

  1. A user or agent attempts to invoke the Skill and receives an oo: command not found error.
  2. The agent follows the first-time setup instructions in SKILL.md.
  3. The shell retrieves the current response from https://cli.oomol.com/install.sh or https://cli.oomol.com/install.ps1.
  4. The response is passed directly to bash or iex without v ...[truncated 1200 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct pipe-to-shell installation commands.
  2. Direct users to a version-pinned release artifact or trusted platform package manager rather than a mutable installation endpoint.
  3. Require the artifact to be downloaded to a local file before execution.
  4. Publish and verify a cryptographic checksum, such as SHA-256, over the downloaded artifact.
  5. Prefer digital signatures tied to a documented publisher identity and require signature verification before installation.
  6. Display or permit inspection of the downloaded installer before it is executed.
  7. Pin the expected CLI version so future server-side changes cannot silently alter the reviewed payload.
  8. Document that installation should occur as an unprivileged user unless a specific, narrowly scoped operation demonstrably requires elevation.
  9. For managed environments, recommend installation through an organization-approved software distribution channel.
  10. If an installation script remains necessary, fail closed when checksum or signature verification cannot be completed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs running a remote script directly via 'curl ... | bash', which executes unpinned code fetched at runtime with no integrity verification. If the host, network path, or installer is compromised, this can lead to arbitrary code execution on the user's machine, making it especially dangerous in an agentic context where users may trust suggested shell commands.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase 'Use this skill for ANY Klazify request' is overly broad and can cause the agent to invoke the skill for loosely related prompts without sufficient task scoping or user intent verification. Broad routing language increases the chance of inappropriate tool use and expands the attack surface for prompt-injection or misuse through ambiguous requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description limits the skill to Klazify requests for searching and reading data. However, the documented behavior instructs running curl ... | bash / PowerShell install scripts and oo auth login, which perform local system changes and account-auth flows rather than merely reading Klazify data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The safety section frames the available actions as read-only and safe, yet the same skill documentation instructs users to perform external account connection and billing remediation steps. Those are operational capabilities outside the manifest's stated scope of searching and reading Klazify data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.