Back to skill

Security audit

OpenSea

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent OpenSea read-only connector, but its setup instructions include unverified remote installer scripts that could run arbitrary local code if followed.

Review the first-time setup before installing. Prefer installing the oo CLI from a verified official release or package manager with checksum/signature validation, and do not let an agent run the remote installer commands automatically unless you accept that local code-execution risk.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote Shell Script Execution via curl and Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction streams a mutable remote response directly into Bash. No fixed release version, cryptographic checksum, digital signature, or manual review step is used before execution. HTTPS authenticates and encrypts the connection under normal conditions, but it does not ensure that the remote server will always return the same reviewed installer.

If the vendor host, publishing account, CDN, DNS resolution, or installer release process is compromised, the response can contain arbitrary shell commands. Those commands execute immediately with the privileges of the user running the installation.

The Skill's declared OpenSea functionality only requires invoking an installed oo CLI for API queries. Arbitrary remote shell execution is therefore not the minimum privilege necessary to perform the declared read operations.

Attack Path

  1. A user or agent attempts an OpenSea action and receives an oo: command not found error.
  2. The user or agent follows the documented first-time installation instruction.
  3. An attacker compromises or gains control over the installer delivery path or upstream publishing infrastructure.
  4. curl retrieves the attacker-controlled response from the expected URL.
  5. The shell pipeline passes that response directly to Bash without verification.
  6. Bash executes the payload with the invoking user's permissions.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking account. The payload could read accessible files and credentials, modify project or user files, install additional software, alter shell configuration, or establish persistence where the acc ...[truncated 166 chars]

Remediation
View remediation

Remediation Suggestions

Remove the pipe-to-shell installation pattern. Use a hardened installation process that:

  1. Pins the CLI to a specific reviewed release and immutable artifact URL.
  2. Downloads the artifact to a local file without executing it.
  3. Verifies a vendor-published cryptographic checksum and, preferably, a digital signature whose trust key is distributed independently.
  4. Stops installation if verification fails.
  5. Allows the user to inspect the artifact and explicitly approve execution.
  6. Executes the installer without elevated privileges unless a documented operation strictly requires them.
  7. Uses a trusted package manager or signed package repository where available.

The Skill should preferably tell users to install the CLI manually from documented, versioned releases rather than allowing an agent to execute an installer automatically.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:67
Finding

Unverified Remote PowerShell Script Execution via Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

irm retrieves the current content of a remote PowerShell script, and iex evaluates that content immediately as PowerShell code. The instruction does not pin an immutable release or verify a checksum or digital signature before execution.

The effective code can therefore change after the Skill has been audited. A compromise of the vendor domain, hosting infrastructure, publishing credentials, DNS path, or release process could replace the expected installer with arbitrary PowerShell commands. The use of Invoke-Expression eliminates a meaningful inspection boundary between download and execution.

Installing the CLI may be necessary for first-time use, but executing mutable network content directly is broader than the privileges required for the Skill's declared OpenSea query functionality.

Attack Path

  1. A Windows user or agent encounters an oo: command not found failure.
  2. The documented PowerShell installation command is executed.
  3. An attacker controls or compromises the script's delivery or publishing path.
  4. Invoke-RestMethod downloads the modified script from the expected URL.
  5. The pipeline forwards the response directly to Invoke-Expression.
  6. PowerShell executes the attacker-controlled commands in the user's current security context.

Impact Assessment

Exploitation grants arbitrary PowerShell execution with the invoking user's permissions. An attacker could access files and credentials available to that user, modify user or project configuration, download additional payloads, or configure persistence when permitted. Execution from an elevated PowerShell session would expose administrator-level resou ...[truncated 48 chars]

Remediation
View remediation

Remediation Suggestions

Remove the irm ... | iex pattern. Replace it with a process that:

  1. References a specific, immutable CLI release.
  2. Downloads the installer to disk without evaluating it.
  3. Validates an Authenticode signature or independently published cryptographic hash.
  4. Rejects unsigned, mismatched, or unexpectedly changed artifacts.
  5. Presents the verified file and intended changes for explicit user approval.
  6. Runs with standard-user privileges whenever possible.
  7. Prefers a signed MSI, Microsoft Store package, or trusted package-manager source over dynamic script evaluation.

Agent instructions should not automatically install software. They should direct the user to a verified installation guide and require explicit approval before any local execution.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into the shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the install endpoint, transport, or upstream distribution is compromised, arbitrary code will run immediately on the host with the agent user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY OpenSea request" and "Whenever a task involves OpenSea," which is a very broad activation condition for a markdown skill file. This lacks limiting examples or exclusion conditions, so ordinary mentions of OpenSea could unintentionally trigger the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.