Back to skill

Security audit

Parseur

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Parseur reader, but its fallback setup tells users to run mutable remote installer scripts directly in a shell.

Review the oo CLI installation path before installing. Prefer an official package manager, pinned release, or a downloaded installer verified by checksum/signature rather than running the provided pipe-to-shell commands. Also confirm you are comfortable giving OOMOL-connected Parseur read access to mailbox and document data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unpinned Remote Installation Scripts Executed Directly by Shell

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The setup instructions download mutable scripts from external URLs and immediately execute them with Bash or PowerShell. The commands do not pin an installer version, validate a cryptographic checksum, verify a digital signature, or provide an opportunity to inspect the downloaded content before execution. HTTPS protects the connection in transit under normal conditions, but it does not establish that the response is a specific reviewed artifact. If the hosting service, DNS, TLS infrastructure, account, or release pipeline is compromised, the effective payload can be changed after this Skill has been audited. Installing the CLI is relevant to the declared Parseur connector functionality and is presented only as a fallback when `oo` is unavailable. Nevertheless, direct pipe-to-shell execution exceeds the minimum safe installation mechanism because it delegates arbitrary code execution to a mutable remote response. The equivalent Windows command has the same weakness: `irm` retrieves remote content and `iex` evaluates it as PowerShell code. ### Attack Path 1. The `oo` CLI is absent, causing an `oo: command not found` error. 2. The agent or user follows the fallback setup instructions in `SKILL.md`. 3. An attacker compromises or gains control over the installer host, publishing pipeline, domain, or another component capable of changing the remote response. 4. The `curl | bash` or `irm | iex` pipeline downloads the attacker-controlled response ...[truncated 1124 chars]
Remediation
View remediation
/install.sh" printf '%s %s\n' "" "oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.sh ``` The actual URL, version, digest, and signature-verification procedure must come from the CLI publisher's authenticated release documentation. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The first-time setup instructions include piping a remotely fetched script directly into bash, which is a classic unsafe installation pattern. If the remote host, CDN path, transport, or published script is compromised, the user could execute attacker-controlled code with their local privileges.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and routing guidance instruct the agent to use this skill for ANY Parseur-related request, creating an unnecessarily broad trigger surface. That can cause the agent to invoke this skill in contexts where direct API use, narrower tooling, or additional user confirmation would be more appropriate, increasing the chance of unintended data access or misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.