Back to skill

Security audit

PostGrid Verify

Security checks for vulnerabilities and agentic risk

Overview

The PostGrid Verify integration is mostly coherent, but its fallback setup tells users to execute unverified remote installer scripts.

Install only if you are comfortable using OOMOL as the PostGrid Verify connector. Do not let an agent run the documented `curl | bash` or `irm | iex` commands directly; install the oo CLI through a verifiable official release or package manager, avoid administrator shells, and confirm any account connection or payload before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Shell Script Retrieval and Execution

Content
View full analysis
Remediation
View remediation
/install.sh" echo " install.sh" | sha256sum -c - less install.sh bash install.sh ``` The checksum and URL must correspond to a fixed release and come from trusted, independently verifiable release metadata. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote PowerShell Script Retrieval and Execution

Content
View full analysis
Remediation
View remediation
/install.ps1" -OutFile ".\install.ps1" if ((Get-FileHash ".\install.ps1" -Algorithm SHA256).Hash -ne "") { throw "Installer hash verification failed" } if ((Get-AuthenticodeSignature ".\install.ps1").Status -ne "Valid") { throw "Installer signature verification failed" } Get-Content ".\install.ps1" & ".\install.ps1" ``` The expected hash, signer identity, and fixed release URL must be documented and distributed through a trusted channel. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a shell one-liner that downloads a remote script and pipes it directly into bash, which creates a supply-chain and remote code execution risk if the hosting endpoint, transport, or script content is compromised. Because this appears in setup instructions for an agent-operated skill, it increases the chance an automated system or operator will execute it without independent verification.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use this skill for "ANY PostGrid Verify request" and "Whenever a task involves PostGrid Verify," which is broad and lacks boundaries for when the skill should or should not activate. It does not provide exclusions or negative examples, so routine mentions of PostGrid Verify could be interpreted as triggers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.