Back to skill

Security audit

lemlist

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a normal read-only lemlist connector, but its fallback setup tells the agent to run unverified remote installer scripts if the required CLI is missing.

Review before installing. The day-to-day lemlist actions are read-only, but do not let an agent automatically run the documented installer commands. Install the oo CLI only from a trusted, verified source, prefer a pinned release or package manager, and confirm any authentication or connection steps yourself.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions pipe a remotely hosted installation script directly into Bash. The command does not pin a reviewed release, validate a cryptographic checksum, or verify a publisher signature before execution. Consequently, the code that ultimately runs can change after the Skill has been reviewed.

HTTPS provides transport protection but does not establish the long-term integrity of the installer. If the hosting account, server, DNS resolution, certificate issuance path, or release pipeline is compromised, the downloaded script could contain attacker-controlled commands. The fallback-only placement reduces how often the command is used but does not eliminate the vulnerability.

This behavior exceeds the minimum privileges required for the declared read-only lemlist functionality. Reading lemlist data requires an installed connector client and network access, whereas running the installer permits unspecified remote code to act with all privileges available to the invoking user.

Attack Path

  1. The oo CLI is absent, causing an oo: command not found error.
  2. The user or Agent follows the documented first-time setup fallback.
  3. The command downloads the current contents of https://cli.oomol.com/install.sh.
  4. The downloaded content is passed directly to Bash without prior inspection or integrity verification.
  5. If the distribution endpoint or pipeline is compromised, attacker-controlled shell commands execute under the invoking user's account.

Impact Assessment

A malicious installer could read or modify any data accessible to the invoking user, including local application data and credentials; alter shell configuration; ...[truncated 314 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation pattern.
  • Direct users to a version-pinned release artifact from an authenticated release page.
  • Download the artifact to a local file without executing it immediately.
  • Publish and verify a SHA-256 digest or, preferably, a cryptographic publisher signature before installation.
  • Allow the user to inspect the installer before execution.
  • Require explicit user approval before installing software.
  • Run installation with ordinary user privileges unless a narrowly scoped privileged operation is demonstrably required.
  • Document the exact files, permissions, and network endpoints used by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote PowerShell Script Execution via Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup command retrieves mutable PowerShell content with Invoke-RestMethod (irm) and immediately evaluates it with Invoke-Expression (iex). There is no pinned version, Authenticode verification, checksum validation, or opportunity to inspect the downloaded script before execution.

The effective payload is controlled by whatever content the remote endpoint returns at execution time. Compromise of the hosting infrastructure, publishing pipeline, or related trust path could therefore convert this documented installation step into arbitrary PowerShell execution.

This capability is broader than required for the Skill's stated purpose. The normal Skill operations only need to invoke the preinstalled oo connector client to retrieve lemlist data; they do not inherently require arbitrary remote code execution on the Windows host.

Attack Path

  1. The oo CLI is unavailable on a Windows system.
  2. The user or Agent follows the first-time setup instructions.
  3. Invoke-RestMethod retrieves the current script from https://cli.oomol.com/install.ps1.
  4. The pipeline passes the response directly to Invoke-Expression.
  5. If attacker-controlled content is returned, it executes immediately with the current PowerShell process's privileges.

Impact Assessment

Exploitation could provide access to files, credentials, and application data available to the current Windows user. It could also modify user configuration, download additional payloads, or execute operating-system commands. If PowerShell is elevated, system-wide compromise may be possible. The audited content does not itself demonstrate persistence, privilege escalati ...[truncated 89 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex pattern and never evaluate a network response directly.
  • Distribute a version-pinned installer or package through a documented release channel.
  • Save the installer locally before running it.
  • Verify both a published cryptographic checksum and the installer's Authenticode signature.
  • Abort installation if the signature, signer identity, version, or checksum is unexpected.
  • Present the intended installation effects and request explicit user confirmation.
  • Avoid elevated PowerShell unless a specific installation operation requires it, and narrowly scope any elevation.
  • Prefer a package manager that validates signed metadata and immutable package versions.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends piping a remotely fetched installer script directly into a shell (curl ... | bash). If the hosting endpoint, transport, or upstream release process is compromised, arbitrary code will execute immediately on the user's system without review, making this a classic supply-chain and remote code execution risk.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses an extremely broad activation condition: 'Use this skill for ANY lemlist request.' This lacks scope boundaries or negative examples, so ordinary mentions of lemlist could trigger the skill unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.