Back to skill

Security audit

Linux DO

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly read-only for Linux DO, but its setup instructions execute an unverified remote installer, so it should be reviewed before use.

Install only if you already trust OOMOL and are comfortable with its CLI. Prefer installing oo from a verified, versioned release or package manager rather than running the pasted remote shell commands directly.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:67
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 67–71
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from an external server and immediately execute them through Bash or PowerShell. Neither command pins a reviewed release, verifies a cryptographic checksum or signature, nor gives the user an opportunity to inspect the downloaded script before execution.

The effective installation payload is not included in the audited project. Consequently, its behavior can change after this Skill has been reviewed. A compromise of the installer host, publishing infrastructure, DNS or TLS trust chain, or an authorized upstream account could convert these setup commands into an arbitrary-code-execution channel.

Installation is only conditionally suggested when oo is unavailable, which reduces routine exposure. Nevertheless, automatically executing remote code exceeds the minimum privileges needed for the Skill's declared read-only Linux DO operations. The safer prerequisite model is to require a separately installed and verified CLI.

Attack Path

  1. The agent attempts to perform a Linux DO action and receives an oo: command not found error.
  2. The Skill directs the agent or user to run one of the first-time installation commands.
  3. The command retrieves the current installer from cli.oomol.com.
  4. If the remote installer or its delivery infrastructure has been compromised, attacker-controlled content is returned.
  5. The shell executes that content immediately without integrity or authenticity verification.
  6. The payload can perform arbitrary actions available to the account that launched Bash or ...[truncated 731 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all curl | bash and irm | iex installation instructions.
  2. Treat the oo CLI as an explicit prerequisite and direct users to a documented, official release page.
  3. Pin the installation instructions to a specific reviewed CLI version rather than a mutable installer URL.
  4. Download the installation artifact to disk without executing it:
    • Use strict HTTPS certificate validation.
    • Use a predictable destination that cannot be replaced through an unsafe temporary-file race.
    • Do not automatically grant executable permissions or launch the artifact.
  5. Publish and verify a cryptographic checksum and, preferably, a signature whose verification key is distributed through a separate trusted channel.
  6. Display the artifact, version, source, expected checksum, and planned installation effects to the user.
  7. Require explicit user approval before executing any installer.
  8. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation. Prompt separately for every privileged operation.
  9. Prefer a trusted package manager or signed platform-specific package that supports version pinning and provenance verification.
  10. Fail safely when verification is unavailable or unsuccessful; do not fall back to executing an unverified script.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network with the user's privileges, enabling supply-chain compromise, MITM-related execution in weaker environments, or malicious changes if the host or delivery path is compromised.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Static analysis

No suspicious patterns detected.