Back to skill

Security audit

OKSign

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent read-only OKSign connector, but its setup instructions tell users to run unverified remote installer scripts that can execute arbitrary local code.

Review before installing. Routine OKSign reads appear purpose-aligned, but do not run the documented installer commands unless you trust the OOMOL installer source and accept the risk of executing a remote script. Prefer a verified, signed, or package-manager installation path for the oo CLI if available.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Shell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The setup command downloads a mutable shell script from an external server and pipes it directly into bash. It provides no version pinning, cryptographic signature verification, checksum validation, or opportunity to inspect the downloaded artifact before execution.

HTTPS protects the connection in transit, but it does not establish that the current script is the same artifact that was reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, or installer pipeline could cause arbitrary attacker-controlled commands to execute. This installation behavior also exceeds the routine Bash(oo *) tool boundary declared by the Skill because it requires a general-purpose shell to execute externally supplied code.

Attack Path

  1. The oo command is absent, causing the documented first-time setup fallback to be used.
  2. An attacker compromises or gains control over the installer endpoint or its release pipeline.
  3. The endpoint serves a modified install.sh payload.
  4. curl sends the response directly to bash without validation or review.
  5. The payload executes with the privileges of the user running the setup command.
  6. The payload can access that user's files and credentials, modify local tools, install persistence mechanisms, or transmit data to attacker-controlled infrastructure.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. The accessible scope includes files, environment data, credentials, network resources, and applications available to that user. If the command is run from a privileged shell, the impact can extend to system-wide m ...[truncated 215 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe downloaded content directly into a shell.
  • Distribute the CLI through a trusted package manager or a version-pinned official release.
  • Download the installer or binary to a local file as a separate step.
  • Verify a vendor-provided cryptographic signature or a SHA-256 checksum obtained through an independently authenticated channel.
  • Pin the expected installer or release version so its effective contents cannot change silently after review.
  • Permit inspection of the downloaded file before execution.
  • Run installation with the least-privileged account possible and avoid requesting elevated privileges unless a documented operation strictly requires them.
  • Document the files, permissions, and network endpoints used by the installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote PowerShell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell setup command retrieves mutable content from an external URL using Invoke-RestMethod (irm) and immediately evaluates it using Invoke-Expression (iex). No fixed version, Authenticode validation, checksum verification, or local inspection boundary is present.

Invoke-Expression treats the response body as executable PowerShell code. Consequently, any party able to alter the endpoint's response can execute arbitrary commands in the caller's PowerShell context. TLS alone does not mitigate compromise of the vendor infrastructure, publishing credentials, DNS, or upstream deployment process.

Attack Path

  1. The oo CLI is unavailable on a Windows host.
  2. The user or agent follows the documented PowerShell installation command.
  3. An attacker controlling or compromising the installer endpoint supplies a modified install.ps1.
  4. Invoke-RestMethod retrieves the attacker-controlled response.
  5. The pipeline passes the response directly to Invoke-Expression.
  6. PowerShell executes the payload with the current process privileges, allowing subsequent access, modification, persistence, or exfiltration actions within that security context.

Impact Assessment

Exploitation yields arbitrary PowerShell execution with the invoking user's privileges. An attacker could read accessible files and credentials, alter user configuration and local executables, contact external systems, or establish persistence. If PowerShell is running with administrator rights, the payload may obtain system-wide control. The behavior is not necessary for routine OKSign read operations and expands the Skill's effective execution bound ...[truncated 17 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern.
  • Publish a signed, versioned installer through an official and authenticated release channel or trusted Windows package manager.
  • Download the installer to disk without executing it automatically.
  • Validate its Authenticode signature and publisher identity before execution.
  • Where signature verification is unavailable, publish and verify a version-specific SHA-256 checksum over an independently authenticated channel.
  • Avoid Invoke-Expression; execute only a verified local artifact using an explicit PowerShell path and a restrictive execution policy.
  • Use a non-administrative PowerShell session unless elevation is demonstrably required.
  • Clearly document the installer's expected filesystem, registry, process, and network changes.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remote script directly from the network without prior verification or integrity checking. If the distribution endpoint, network path, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says to use this skill for ANY OKSign request and instead of calling the API directly, which creates an overly broad routing trigger. That can cause unrelated or sensitive OKSign-adjacent tasks to be funneled through this skill without sufficient task-specific guardrails, increasing the chance of inappropriate data access or unsafe action selection if the skill is auto-invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.