Back to skill

Security audit

lexoffice

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Lexoffice through OOMOL, but its setup guidance includes unsafe remote installer commands that can execute changing network code on the user's machine.

Review this skill before installing if the oo CLI is not already present. Prefer installing the CLI through a verified, version-pinned method with checksum or signature verification rather than piping a downloaded script directly into Bash or PowerShell. For normal use after setup, confirm exact payloads before create or update actions because they can change Lexoffice business data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Unverified Remote Installer Scripts Executed Directly in a Shell

Content
View full analysis
Remediation
View remediation
/oo-cli.tar.gz" echo " oo-cli.tar.gz" | sha256sum --check - # Extract and install only after successful verification and explicit approval. ``` The actual release URL, version, and checksum must come from the official publisher and must not use placeholders. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent/user to install software by piping a remotely fetched script directly into bash, which is a well-known unsafe pattern because the downloaded content is executed without verification, pinning, or integrity checks. In this skill context, the risk is elevated because the setup step is embedded in operational guidance for a connector, so an agent may surface or encourage execution of arbitrary remote code if the CLI is missing.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Static analysis

No suspicious patterns detected.