Back to skill

Security audit

Neon

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Neon connector, but its setup path tells users to execute a remote installer directly and it can perform account-changing Neon actions.

Review the setup instructions before installing. Prefer installing the oo CLI from a verified, versioned, checksum- or signature-validated source instead of piping a downloaded script into a shell. Use this skill only for Neon account operations you intend to perform, and confirm exact targets before write or delete actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:72
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72–76
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions pipe network responses directly into Bash or PowerShell. The downloaded scripts are not pinned to an immutable release, inspected before execution, or validated using a repository-pinned checksum or cryptographic signature.

Although the scripts are served over HTTPS from a vendor-branded domain, HTTPS only protects transport to the endpoint currently controlling that domain. It does not guarantee that the installer remains unchanged after the Skill has been reviewed. Compromise of the hosting infrastructure, vendor account, DNS configuration, TLS termination environment, or installer publishing process could therefore turn these commands into an arbitrary-code execution channel.

This behavior is not necessary for the Skill's core Neon connector operations because those operations only require an already installed oo CLI. Installation also exceeds the privileges needed merely to document the connector or report that its prerequisite is absent.

Attack Path

  1. An attacker compromises or gains control over cli.oomol.com, its installer publishing process, or another component capable of changing an installer response.
  2. The attacker replaces install.sh or install.ps1 with a malicious payload.
  3. The oo command is unavailable, causing the Skill's first-time setup instructions to be used.
  4. The agent or user runs the documented command.
  5. curl or irm retrieves the attacker's current response.
  6. Bash or PowerShell executes that response immediately without integrity verification or an inspection boundary.
  7. The payload operates with the permissi ...[truncated 831 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation commands.
  2. Direct users to a documented release page or trusted platform package manager instead of automatically executing a network response.
  3. Pin the CLI to a specific reviewed version rather than retrieving a mutable latest installer.
  4. Download the installation artifact to a local file without executing it immediately.
  5. Verify the artifact using a SHA-256 digest stored in a trusted, version-controlled location or a cryptographic signature whose public key is distributed independently.
  6. Execute the artifact only after successful verification and explicit user approval.
  7. Avoid requesting administrator privileges unless a specific installation step demonstrably requires them.
  8. Keep CLI installation outside the Skill's normal action flow. When the prerequisite is absent, report the condition and provide safe manual installation guidance rather than executing an installer automatically.
  9. For PowerShell, avoid Invoke-Expression; use a signed, versioned package and enforce signature validation.
  10. For macOS and Linux, prefer a signed package or pinned package-manager formula with provenance and integrity controls.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install the CLI via a remote shell pipeline (curl ... | bash), which executes code fetched from the network without prior verification. If the install endpoint, transport, DNS, or upstream distribution is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's invocation guidance says to use it for ANY Neon request, which is overly broad and can cause the agent to route all Neon-related tasks through this skill without sufficient task-level filtering. In practice, this increases the chance of unintended execution of state-changing or destructive connector actions when a request is ambiguous or when a safer non-executing path would be more appropriate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.