Back to skill

Security audit

Mopinion

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Mopinion access, but its first-time setup tells users to run remote installer scripts directly in a shell, so it should be reviewed before installation.

Before installing, prefer a safer oo CLI installation method such as a versioned package or installer with checksum or signature verification. Use a least-privileged Mopinion/OOMOL connection where possible, and be aware that the skill can read feedback and account data available through that connected account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions retrieve mutable scripts from an external URL and execute them immediately through Bash or PowerShell. Neither command pins a script or CLI version, verifies a cryptographic signature or checksum, nor saves the payload for inspection before execution.

HTTPS protects the connection in transit but does not establish payload immutability or protect users if the hosting server, publishing account, domain, or release process is compromised. The effective code can therefore change after the Skill has been reviewed. The PowerShell Invoke-Expression pattern has the same security properties as piping the response into Bash.

Installing the CLI may be necessary when oo is unavailable, but immediate execution of unverified network content exceeds the minimum mechanism needed to provide installation guidance.

Attack Path

  1. The oo command is absent, causing the user or agent to follow the first-time setup instructions.
  2. An attacker compromises or gains control over the remote script endpoint, its publishing pipeline, or associated infrastructure.
  3. The attacker replaces the installation response with arbitrary shell commands.
  4. curl ... | bash or irm ... | iex executes the current response without integrity validation or prior review.
  5. The payload operates with the privileges of the invoking shell and can access resources available to that user.

Impact

...[truncated 632 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace direct pipe-to-shell and Invoke-Expression instructions with installation through a reputable platform package manager or a pinned release artifact.
  2. Pin an explicit CLI version rather than downloading a mutable installer from a generic endpoint.
  3. Download the artifact to disk without executing it, then verify a vendor-published cryptographic signature or strong checksum obtained through an independently authenticated channel.
  4. Allow the user to inspect the downloaded script and require explicit approval before execution.
  5. Document the permissions required by the installer and advise users to run it without elevated privileges unless a specific, justified step requires elevation.
  6. Publish reproducible release artifacts and retain versioned checksums or signatures so reviewed installation content cannot be changed silently.
  7. For PowerShell, avoid Invoke-Expression; use a signed, versioned package or save and validate the installer before launching it with a constrained execution policy.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the install endpoint, transport, hosting account, or delivery path is compromised, arbitrary code will run immediately on the user's system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Mopinion request" and "Whenever a task involves Mopinion," which is a broad activation condition without clear boundaries or exclusions. In a manifest file, this can cause unintended invocation for loosely related conversations that merely mention Mopinion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.