Back to skill

Security audit

Placid

Security checks for vulnerabilities and agentic risk

Overview

This Placid connector skill is mostly coherent, but its setup instructions tell agents to run unverified remote installer scripts, which is too risky for automatic skill-guided installation.

Review the setup path before installing. Use this skill only if you are comfortable with OOMOL's oo CLI and prefer a verified or manually inspected installer instead of running the provided one-line remote execution commands. Confirm all create and delete payloads before allowing Placid changes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction pipes a remotely downloaded, mutable shell script directly into Bash. The command does not pin a reviewed release, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded content before execution.

Although the hostname is consistent with the declared OOMOL service, the repository does not contain the script or evidence that its content is immutable and trusted. Consequently, the effective payload can change after this Skill has been reviewed. This behavior exceeds the minimum privileges needed to operate the Placid connector: connector operations require the oo CLI, but they do not inherently require arbitrary remote code to be executed without verification.

Attack Path

  1. The oo command is unavailable, causing the agent or user to consult the first-time setup instructions.
  2. An attacker compromises the installation script, its hosting account, the serving infrastructure, or another relevant supply-chain component.
  3. The victim runs the documented curl pipeline.
  4. curl retrieves the attacker-controlled script and passes it directly to Bash.
  5. Bash executes the payload with the permissions of the invoking account, without integrity validation or prior inspection.

Impact Assessment

A malicious installation payload could execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the host configuration, it could read or modify accessible files, steal local credentials and tokens, alter development tools, install persistence, or download additional payloads. The reviewed Skill does not itself request elevated privileges, s ...[truncated 142 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Prefer installation through a trusted operating-system package manager or a vendor package repository with signed metadata.
  • Pin the CLI to a specific reviewed version rather than downloading a mutable latest installer.
  • Download the installer to a local file first, then verify a vendor-provided cryptographic signature and a pinned SHA-256 digest before execution.
  • Publish the expected digest through a separate authenticated channel and fail closed if verification does not succeed.
  • Require explicit user approval before installing software or executing an installer.
  • Run installation with the minimum necessary account privileges and avoid requesting administrative privileges unless strictly required.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows installation instruction downloads a mutable PowerShell script with Invoke-RestMethod (irm) and immediately executes its content using Invoke-Expression (iex). It provides no version pinning, checksum verification, signature validation, or manual inspection boundary.

Because the executable content remains external to the audited project, it can be replaced after review. Trust in the apparent vendor domain does not eliminate the risk of a compromised hosting account, deployment pipeline, server, or installation script. Arbitrary remote script execution is broader than the privileges necessary to invoke the declared Placid connector functionality.

Attack Path

  1. The oo CLI is missing on a Windows system.
  2. The agent or user follows the documented first-time installation command.
  3. An attacker has modified or replaced the remotely hosted PowerShell installer through compromise of its supply chain or hosting infrastructure.
  4. irm retrieves the attacker-controlled script as network content.
  5. The pipeline sends that content directly to iex.
  6. PowerShell executes the payload under the invoking user's security context without validating its provenance or integrity.

Impact Assessment

The payload could perform any action permitted to the invoking Windows account, including reading or changing accessible files, extracting credentials or API tokens, modifying the user's PowerShell profile, altering local tools, downloading additional executables, or establishing user-level persistence. Administrator-level compromise is possible only if the command is run from an elevated PowerShell session or the payload ...[truncated 106 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex execution pattern.
  • Distribute the CLI through a trusted, signed Windows package mechanism where possible.
  • Pin a specific reviewed CLI release.
  • Download the installer as a file and verify an Authenticode signature and a pinned cryptographic digest before execution.
  • Reject unsigned, invalidly signed, or hash-mismatched installers.
  • Allow the user to inspect the script before running it and obtain explicit approval for installation.
  • Execute the installer without administrative privileges unless elevation is demonstrably necessary.
  • Document the expected publisher identity and verification commands so users can independently validate the artifact.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software via a remote script piped directly into a shell (curl ... | bash). This pattern is dangerous because it executes unverified code fetched at runtime from the network, creating a supply-chain and remote code execution risk if the host, transport, script content, or distribution channel is compromised.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use this skill for 'ANY Placid request' and 'instead of calling the API directly,' which is an overly broad routing trigger. Broad invocation criteria can cause the agent to select this skill in situations where a narrower, safer, or more context-appropriate path should be used, increasing the chance of unintended writes or destructive actions being exposed through normal task routing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.