Back to skill

Security audit

ngrok

Security checks for vulnerabilities and agentic risk

Overview

This ngrok connector skill is mostly coherent, but its setup instructions tell users to run an unverified remote installer directly in a shell.

Install only if you trust OOMOL as an intermediary for your ngrok account. Prefer a verified or package-manager installation of the oo CLI, avoid running the remote installer from an elevated shell, and treat the skill as suitable for reading ngrok account resources rather than for every casual mention of ngrok.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from cli.oomol.com and pass their contents directly to Bash or PowerShell. No version is pinned, and neither command verifies a cryptographic signature or checksum before execution. The user also has no mandatory opportunity to inspect the downloaded code.

Installing the oo CLI may be necessary when it is absent, but executing an unverified network response directly in a shell exceeds the minimum safe installation mechanism. The effective installer can change after the Skill has been audited. Although the file identifies this as an OOMOL domain, the audited project contains no evidence establishing the integrity of every future response from that domain.

Attack Path

  1. An attempted connector command fails because the oo CLI is unavailable.
  2. The user or agent follows the documented first-time setup command.
  3. The command retrieves the current installer response from cli.oomol.com.
  4. An attacker who compromises the distribution server, installer publication process, or relevant network/trust infrastructure supplies modified script content.
  5. Bash or PowerShell executes that content immediately, without integrity verification or prior inspection.
  6. The payload performs arbitrary actions using the permissions of the account that invoked the installation command.

Impact Assessment

Successful exploitation provides arbitrary code execution with the invoking user's privileges. Depending on those privileges and the attacker's payload, the affected scope can include local file ...[truncated 454 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace direct curl | bash and irm | iex execution with installation through a trusted platform package manager where possible.
  2. Pin the CLI to an explicit release version rather than retrieving a mutable generic installer.
  3. Download the installer or release artifact to a local file without executing it.
  4. Publish a cryptographic checksum or signature through an independently protected release channel and verify it before execution.
  5. Abort installation if signature, checksum, expected publisher, or pinned-version validation fails.
  6. Allow the user to inspect the downloaded script and require explicit approval before running it.
  7. Run the installer with ordinary user privileges unless a documented installation step strictly requires elevation.
  8. Document the files, configuration changes, and network endpoints used by the installer so users can evaluate its scope.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to execute a remote installation script via curl ... | bash, which is a well-known unsafe pattern because it grants immediate shell execution to content fetched over the network. If the remote server, distribution path, or TLS trust chain is compromised, an attacker can execute arbitrary code on the user's machine under the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY ngrok request" and "Whenever a task involves ngrok," which is a very broad activation condition. It does not define boundaries, exclusions, or negative examples, so ordinary mentions of ngrok could trigger the skill unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.