Back to skill

Security audit

Lob

Security checks for vulnerabilities and agentic risk

Overview

This Lob connector skill is mostly coherent, but it includes unsafe first-time setup commands that execute remote installer scripts directly.

Review this skill before installing. Routine Lob address lookup behavior is understandable, but avoid letting an agent run the remote installer commands automatically; install the oo CLI through a trusted, versioned, verifiable process and be aware that address data entered for verification will be sent to the connected Lob/OOMOL service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installation Scripts Are Downloaded and Executed Directly

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The setup instructions pipe remotely downloaded scripts directly into Bash or PowerShell. The remote content is executed immediately without being saved for inspection, pinned to a reviewed version, or verified using a cryptographic signature or checksum. Although `cli.oomol.com` is consistent with the service named by the Skill, the scripts are mutable external resources. Compromise of the hosting service, DNS infrastructure, TLS termination, deployment pipeline, or vendor account could change the effective payload after the Skill has been reviewed. The Skill would then direct execution of attacker-controlled commands. Installing software is not required for normal Lob address-verification operations when the `oo` CLI is already present. Consequently, automatic or agent-directed execution of an unverified installer exceeds the minimum privileges necessary for the Skill's ordinary functionality. ### Attack Path 1. The `oo` command is absent or made unavailable in the execution environment. 2. An agent or user follows the documented first-time setup instructions. 3. `curl` or `irm` retrieves the current installer from `cli.oomol.com`. 4. The response is passed directly to Bash or `Invoke-Expression` without integrity verification or inspection. 5. If the remote delivery infrastructure or installer has been compromised, arbitrary attacker-supplied commands execute with the privileges of the invoking user. 6. Those commands can access the ...[truncated 972 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to execute a remote installation script via 'curl ... | bash', which is a classic unsafe pattern because it fetches and immediately executes code from the network without verification. If the remote host, transport, or script content is compromised, this can result in arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to use this skill for 'ANY Lob request' and whenever a task 'involves Lob' is overly broad and can trigger the skill for tangential or ambiguous tasks. In an agentic environment, that increases the chance of unnecessary connector use, unintended data disclosure to the Lob integration path, or bypass of more appropriate task-specific safeguards.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The safety section asserts that untagged actions are reads, but the listed untagged actions perform address verification and standardization against an external service. Misclassifying these operations as harmless reads can cause an agent to send user-supplied address data to Lob without appropriate disclosure or confirmation, creating privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest limits the skill's purpose to Lob requests involving 'searching and reading data,' which implies a read-oriented scope. However, the file also instructs use of oo auth login and visiting a connection URL to establish or refresh credentials, which are account-management operations not reflected in that description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.