Back to skill

Security audit

Motion

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Motion integration, but its first-time setup recommends executing unverified remote installer scripts, which users should review before installing.

Install only if you are comfortable using OOMOL as a Motion connector and granting it access to your Motion data. Do not blindly run the listed installer commands; prefer an official signed or checksum-verified installation path, and confirm exact payloads before any write or delete action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:67
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction pipes a remotely downloaded script directly into Bash. The script is not pinned to a version, inspected before execution, or verified using a cryptographic checksum or signature. Although HTTPS provides transport protection, it does not prevent execution of a malicious payload if the hosting infrastructure, publisher account, domain, or installation script is compromised.

Because the effective script can change after this Skill has been reviewed, its actual behavior cannot be determined from the audited package. Installing the CLI is also outside the Skill's normal Bash(oo *) operational scope and exceeds the minimum privileges required when the documented prerequisite—that the CLI is already installed—is enforced.

Attack Path

  1. A Motion operation fails because the oo command is unavailable.
  2. The user or agent follows the first-time setup instruction.
  3. curl retrieves the current contents of https://cli.oomol.com/install.sh.
  4. The response is passed directly to Bash without validation or inspection.
  5. If the remote source or delivery infrastructure has been compromised, attacker-controlled shell commands execute with the privileges of the invoking user.

Impact Assessment

A malicious installer could execute arbitrary commands under the invoking account, read or modify accessible files, collect credentials and agent state, install additional software, alter local tools, or establish persistence. If the command is run from a privileged account or subsequently requests elevated privileges, the impact could extend to system-wide compromise. No evidence proves that the currently hosted script is malicious ...[truncated 68 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Treat the CLI as a prerequisite and ask the user to install it manually from an independently verified official release.
  • Pin installation to a specific release and immutable artifact URL.
  • Download the artifact to disk without executing it immediately.
  • Verify a publisher-provided SHA-256 checksum and, preferably, a cryptographic signature using a trusted public key.
  • Display the source, version, destination, and expected changes before requesting explicit user approval.
  • Run installation with ordinary user privileges and avoid elevation unless a documented step strictly requires it.
  • Fail safely when verification cannot be completed.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:71
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 71
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows installation instruction uses Invoke-RestMethod through its irm alias to retrieve a remote PowerShell script and passes the response directly to Invoke-Expression through iex. This causes mutable network content to execute immediately without version pinning, local inspection, checksum validation, or signature verification.

HTTPS does not mitigate compromise of the publisher, hosting environment, domain, or remote script. The payload can also change after the Skill package is audited, preventing the package review from establishing what commands will execute. Installing arbitrary software through PowerShell exceeds the narrow privileges needed to invoke an already installed oo CLI.

Attack Path

  1. A Motion operation fails because the oo command is unavailable on Windows.
  2. The user or agent follows the documented PowerShell setup command.
  3. irm downloads the current contents of https://cli.oomol.com/install.ps1.
  4. The downloaded text is sent directly to iex.
  5. A compromised remote source can execute attacker-controlled PowerShell commands in the user's session.

Impact Assessment

Successful exploitation provides arbitrary PowerShell execution with the invoking user's privileges. An attacker could access user-readable files and credentials, modify the user's environment, install executables, alter PowerShell profiles or local tools, and potentially create persistence. Execution from an administrative shell could result in system-wide compromise. The audit found no evidence that the present remote script is malicious; the confirmed risk is the insecure execution mechanism and mutable trust boundary.

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation instruction.
  • Direct users to a pinned, signed release from a verifiable official distribution channel.
  • Download the PowerShell script or installer as a file before execution.
  • Verify its Authenticode signature and a publisher-provided cryptographic checksum.
  • Require explicit user approval after presenting the pinned version, publisher identity, and intended system changes.
  • Use a constrained, non-administrative PowerShell session whenever possible.
  • Do not modify execution policy globally or disable security controls to facilitate installation.
  • Abort installation if signature or checksum verification fails.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a curl-to-shell pipeline, which executes remote content immediately without verification. If the install endpoint, network path, or hosting is compromised, this can lead to arbitrary code execution on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description says to use this skill for ANY Motion request and instead of calling the API directly, which can cause over-triggering for broad or ambiguous mentions of Motion. That increases the chance the agent invokes a high-privilege integration in contexts where it is unnecessary, potentially exposing connected account data or enabling unintended state-changing operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.