Back to skill

Security audit

Outlook

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Outlook connector, but its setup instructions tell users to run unverified remote installer scripts directly in a shell.

Review this skill before installing. Only use it if you trust OOMOL with Outlook mailbox access, and avoid running the documented pipe-to-shell installer commands unless you have independently verified the installer source and permissions. Confirm any email-sending, draft-changing, or mailbox-settings update before allowing the action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:65-69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from cli.oomol.com and immediately execute them through Bash or PowerShell. Neither command pins an installer version nor verifies a cryptographic signature or checksum. Users and agents therefore cannot inspect or authenticate the effective payload before execution, and the payload can change after the Skill has been reviewed.

HTTPS provides transport protection but does not establish that the downloaded script is safe. Compromise of the hosting server, publishing account, DNS infrastructure, or installer pipeline could cause arbitrary attacker-controlled commands to run. The use of PowerShell Invoke-Expression (iex) and a direct curl | bash pipeline removes the review boundary between retrieval and execution.

Installing a CLI can be necessary for the declared Outlook connector functionality, but immediate execution of unverified remote code exceeds the minimum mechanism required to perform that installation. A verified, version-pinned package or separately downloaded and inspected installer would provide the required functionality with materially lower risk.

Attack Path

  1. The oo CLI is unavailable, causing the user or agent to consult the first-time setup instructions.
  2. The user or agent runs the documented command on macOS, Linux, or Windows.
  3. The command downloads the current script served by cli.oomol.com.
  4. The downloaded content is passed directly to Bash or PowerShell without integrity verification or inspection.
  5. If the remote endpoint or its publishing infrastru ...[truncated 1073 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation patterns.
  2. Direct users to an official, version-pinned release artifact or trusted operating-system package repository.
  3. Publish expected SHA-256 hashes and require verification before execution.
  4. Cryptographically sign release artifacts and document signature verification against a pinned, independently distributed public key.
  5. Separate download and execution into distinct steps so the installer can be inspected before it runs.
  6. Document the installer's required permissions, filesystem changes, network destinations, and rollback procedure.
  7. Advise users to install without administrative privileges unless a specific, justified operation requires elevation.
  8. If automated installation remains necessary, pin the exact release URL and fail closed when checksum or signature validation does not succeed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). That creates a supply-chain and remote code execution risk: if the install endpoint, transport, or hosting is compromised, arbitrary code runs immediately on the local system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Outlook request" and whenever a task involves Outlook, which is broader than a specific invocation condition and overlaps many ordinary email/calendar tasks. It does not provide boundaries, exclusions, or negative examples to clarify when this skill should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.