Back to skill

Security audit

OpenAlex

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for OpenAlex access, but its first-time setup tells users to run unverified remote installer scripts directly in a shell.

Review the install steps before using this skill. Prefer installing the oo CLI through a verified package manager or a downloaded, inspected, checksum-verified installer instead of piping a remote script directly into a shell. For normal OpenAlex queries, the connector behavior is disclosed and appears purpose-aligned.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

The first-time setup instructions provide two platform-specific commands that retrieve mutable scripts from an external server and immediately execute them:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

Both commands pass network responses directly to a command interpreter. The downloaded payload is not pinned to a version and is not validated using a cryptographic signature or expected digest. Users and agents therefore execute whatever content the remote endpoint returns at invocation time, even if that content differs from what existed when the Skill was audited.

The domain is associated with the declared CLI vendor, but domain affiliation does not establish payload integrity. Compromise of the vendor's publishing infrastructure, domain, CDN, DNS resolution, TLS termination, or installer endpoint could replace the expected installer with arbitrary commands.

Installing the CLI is not necessary for normal OpenAlex operations when it is already present. The instructions condition installation on a command not found error, which limits exposure, but executing an unverified remote installer still exceeds the minimum privileges required for ordinary OpenAlex read operations.

The Windows command has the same underlying issue as the flagged curl | bash command: Invoke-RestMethod obtains mutable content and Invoke-Expression immediately interprets it as PowerShell code.

The Skill also sends OpenAlex queries, identifiers, filters, and JSON payloads through the disclosed OOMOL connector. That network processing is consistent with the declared connector-based functionality, and the audited file does not instruct the agen ...[truncated 1510 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that pipe network responses directly into Bash or Invoke-Expression.
  2. Prefer a trusted operating-system package manager or an officially signed, version-pinned release package.
  3. If a standalone installer is unavoidable:
    • Pin the download to a specific immutable release.
    • Download it to a local file instead of executing it directly.
    • Publish an expected SHA-256 or stronger digest through an independent trusted channel.
    • Verify the digest and, preferably, a vendor signature before execution.
    • Allow the user to inspect the downloaded file.
    • Execute it only after explicit user approval.
  4. Document the installer's required permissions and instruct users to run it without administrative privileges unless a specific operation demonstrably requires elevation.
  5. Do not let an agent install the CLI automatically after an error. Return clear installation guidance and require the user to perform or explicitly approve the installation.
  6. Consider replacing the commands with links to a versioned installation guide that explains integrity verification and supported package-manager installation methods.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software via curl ... | bash, which executes a remote script directly without verification. If the remote server, network path, or distribution artifact is compromised, this can lead to arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY OpenAlex request" and "Whenever a task involves OpenAlex," which is an extremely broad activation condition. It does not define narrower trigger phrases, boundaries, or negative examples, so ordinary requests mentioning OpenAlex could invoke the skill unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.