Back to skill

Security audit

OpenGraph.io

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for OpenGraph.io use, but its fallback setup tells the agent to execute remote installers directly, which deserves review before installation.

Install only if you trust OOMOL's CLI distribution path and are comfortable with the agent suggesting remote installer execution during setup. Prefer installing oo yourself from a verified source, checking signatures or checksums where available, and avoid running the setup commands from an elevated shell.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Shell Script Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command downloads a mutable remote script and pipes it directly into Bash. The script is executed without pinning a release version, verifying a cryptographic signature or checksum, or giving the user an opportunity to inspect the downloaded content.

HTTPS protects the connection in transit but does not independently establish the integrity or trustworthiness of the script served by the remote host. If the hosting infrastructure, DNS, certificate issuance, publishing account, or installer itself is compromised, the server can supply arbitrary shell commands. Because the effective payload is retrieved at execution time, it can also differ from the payload available when this Skill was audited.

Installing the required CLI is related to the Skill's functionality, but immediate execution of unverified network content exceeds the minimum risk necessary to perform that installation. A pinned and cryptographically verified release artifact would provide the same functionality with a smaller trust boundary.

Attack Path

  1. The oo CLI is unavailable and an agent or user follows the first-time setup instructions.
  2. The command connects to cli.oomol.com and retrieves the current contents of install.sh.
  3. A compromised publishing pipeline, hosting service, DNS path, certificate authority, or vendor account supplies a modified installer.
  4. Bash executes the response immediately, before the user can inspect or validate it.
  5. The modified installer runs arbitrary commands with the privileges of the user who invoked the installation command.
  6. Those commands can access local data, credentials, environment variables, and netwo ...[truncated 763 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation command.
  • Direct users to a version-pinned release artifact or trusted platform package manager.
  • Download the installer or binary to a local file without executing it automatically.
  • Publish an expected SHA-256 or stronger digest through a separately controlled channel and require verification before execution.
  • Prefer cryptographically signed release artifacts and verify the signature against a documented, pinned publisher key.
  • Require explicit user approval before executing an installer or granting elevated privileges.
  • Run installation with the least-privileged account possible and document any filesystem or network permissions it requires.
  • If a script remains necessary, use a safer sequence such as download, integrity verification, inspection, and then explicit execution.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote PowerShell Script Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

Invoke-RestMethod (irm) retrieves the current contents of a remote PowerShell installer, and Invoke-Expression (iex) immediately evaluates that response as code. No release version is pinned, and no signature, Authenticode status, checksum, or expected content is verified before execution.

This construction makes the external server response an executable payload. It therefore allows the effective behavior to change after review and creates a supply-chain execution path if the hosting domain or release infrastructure is compromised. The vendor-aligned domain and use of HTTPS reduce some transport risks but do not eliminate the need to verify the downloaded artifact.

Installing the CLI is relevant to first-time setup, but evaluating an unverified network response is not necessary to achieve that purpose and violates least-risk installation practices.

Attack Path

  1. The oo CLI is unavailable on a Windows host and the setup instructions are followed.
  2. Invoke-RestMethod retrieves install.ps1 from the external server.
  3. An attacker who has compromised the vendor's hosting, publishing credentials, DNS path, certificate trust path, or installer deployment supplies attacker-controlled PowerShell.
  4. Invoke-Expression executes the response immediately in the current PowerShell process.
  5. The malicious script performs arbitrary actions using the invoking user's privileges.
  6. It may access user files and credentials, contact additional infrastructure, alter PowerShell profiles or other configuration, or deploy follow-on payloads where permissions permit.

Impact Assessment

Exploitation provides arbitrary Po ...[truncated 571 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Distribute a version-pinned package or installer through a trusted package repository or signed release channel.
  • Download the artifact separately and verify its Authenticode signature and expected publisher before execution.
  • Publish and verify a cryptographic checksum obtained through an independently controlled channel.
  • Allow the user to inspect the downloaded script and require explicit approval before it runs.
  • Avoid administrative execution unless installation genuinely requires it, and clearly document any requested elevated operations.
  • Configure installation guidance to fail closed when signature or integrity validation is unsuccessful.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software via curl ... | bash, which executes a remote script directly from the network without verification. If the install endpoint, CDN path, TLS trust chain, or upstream distribution is compromised, this can lead to arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says to use this skill for "ANY OpenGraph.io request" and "Whenever a task involves OpenGraph.io," which is broad enough to match many loosely related requests. It does not provide narrower trigger boundaries or exclusion examples, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.