T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installation Scripts Executed Directly by the Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a Pingdom reading connector, but its setup asks users to execute an unverified remote installer and its scope is broader than a read-only Pingdom helper should be.
Review before installing. Use this skill only for the listed read-only Pingdom actions unless future documentation clearly declares write actions and confirmation requirements. Do not pipe the installer directly into a shell; prefer a pinned, verifiable oo CLI release or inspect and verify the installer before running it. Be aware that OOMOL will mediate Pingdom requests and that setup may create persistent local and account-level state.
SKILL.md:58Unverified Remote Installation Scripts Executed Directly by the Shell
The manifest and description constrain the skill to 'searching and reading data,' but the body explicitly discusses possible [write] and [destructive] actions. That mismatch weakens policy and user expectations, making it easier for an invoking agent or user to authorize this skill under a read-only assumption while the skill contract implicitly permits state-changing operations.
The skill instructs users to execute a remote installation script via 'curl ... | bash', which is a classic supply-chain and arbitrary code execution risk. If the remote endpoint, transport, distribution pipeline, or hosting account is compromised, users may execute attacker-controlled code directly on their machine.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The trigger phrase 'Use this skill for ANY Pingdom request' is overly broad and can cause the agent to invoke the skill in contexts beyond its intended safe scope. Broad auto-routing increases the chance that sensitive, administrative, or unintended tasks are funneled through the skill without sufficient user awareness or task-specific validation.
No suspicious patterns detected.