Back to skill

Security audit

Productlane

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Productlane automation, but its setup instructions include unverified remote installer commands that could execute local code.

Install only if you are comfortable with OOMOL mediating Productlane access and with the listed create, update, and soft-delete capabilities. Avoid running the pipe-to-shell or Invoke-Expression installer commands automatically; prefer a verified package or reviewed installer from the official source, and confirm every write or delete action before it runs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:61-70
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

The first-time setup instructions provide remote-to-interpreter installation commands for both macOS/Linux and Windows:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

These commands retrieve mutable content from cli.oomol.com and immediately execute it with the current user's privileges. They do not pin a version, verify a cryptographic checksum or signature, save the script for inspection, or otherwise establish that the downloaded bytes match an audited release.

Although the hostname is associated with the Skill's declared OOMOL service and the instructions are only a fallback when oo is unavailable, direct download-to-interpreter execution is not necessary to provide Productlane connector functionality. The effective code executed can change after the Skill itself has been reviewed. Compromise of the hosting service, publishing pipeline, domain, DNS resolution, TLS trust chain, or installer content could therefore turn the documented setup process into arbitrary local code execution.

Attack Path

  1. The user or Agent attempts to use the Skill on a system where the oo CLI is unavailable.
  2. It follows the documented first-time setup procedure.
  3. curl or PowerShell downloads a mutable installer response from cli.oomol.com.
  4. The response is passed directly to Bash or PowerShell without integrity verification or review.
  5. If the remote content or its delivery path has been compromised, attacker-controlled commands execute with the invoking user's privileges.
  6. Those commands can access data and resources available to that account and may install further components.

Impact Assessment

Successful ...[truncated 596 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the pipe-to-shell and Invoke-Expression instructions with a trusted package-manager installation or a signed release artifact.
  • Pin the CLI to a specific immutable version rather than retrieving the latest mutable installer.
  • Publish a cryptographic checksum and preferably a signature backed by a documented release key.
  • Download the installer or binary to a local file, verify its signature and checksum, and only then execute it.
  • Display the exact artifact source, version, expected digest, and verification commands in SKILL.md.
  • Run installation with the least-privileged account possible and avoid requesting administrator or root privileges unless strictly required.
  • Apply equivalent verification controls to both the Bash and PowerShell installation paths.
  • Keep installation separate from normal Skill execution; do not allow an Agent to install software automatically without explicit user approval.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell (curl ... | bash), which executes code fetched over the network without prior verification. If the install endpoint, transport, DNS, or hosting is compromised, this can lead to arbitrary code execution on the user's machine; because the skill is a setup guide, users may be especially likely to follow it verbatim.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill for "ANY Productlane request" and "Whenever a task involves Productlane," which is extremely broad and lacks constraints or negative examples. In a markdown skill description, this can overlap with many ordinary Productlane-related tasks and makes the activation boundary unclear.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.