Back to skill

Security audit

Quo (OpenPhone)

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Quo/OpenPhone through OOMOL, but its setup instructions include unverified remote installer scripts executed directly by a shell.

Install only if you are comfortable using OOMOL as the broker for Quo/OpenPhone data and you review the oo CLI installation path first. Avoid piping the installer directly into a shell; prefer official, versioned, verifiable installation steps, and require explicit confirmation before any message-send, update, or delete action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:66
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 66–70
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable content from cli.oomol.com and immediately execute it using Bash or PowerShell. The instructions do not pin a release version, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded script before execution.

HTTPS protects the script while it is in transit, but it does not guarantee that the server will always return the same audited payload. Compromise of the hosting account, publishing pipeline, domain, or server could therefore turn these installation commands into arbitrary code-execution channels. This behavior also prevents the effective installation payload from being fully evaluated as part of the static Skill audit.

Although installing the declared oo CLI is relevant to the Skill's functionality and the instructions only recommend installation after a command-not-found error, direct pipe-to-shell execution exceeds the minimum privilege and integrity requirements necessary to install that tool safely.

Attack Path

  1. The user requests a Quo operation and the oo command is unavailable.
  2. The Skill follows its documented first-time setup fallback.
  3. The Agent or user executes the applicable Bash or PowerShell installation command.
  4. The command retrieves the current script from cli.oomol.com without validating its version, checksum, or publisher signature.
  5. If the remote host or its release pipeline supplies a modified script, the shell executes the attacker's instructions immediately.
  6. The payload runs with the privileges of the invo ...[truncated 1029 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct pipe-to-shell installation commands.
  2. Link to a documented official installation procedure using versioned release artifacts.
  3. Pin the CLI to an explicitly reviewed version rather than downloading a mutable latest installer.
  4. Download the installer or binary to a local file without executing it immediately.
  5. Publish and verify a cryptographic signature from a trusted release key, or at minimum verify a pinned SHA-256 digest obtained through an independently protected channel.
  6. Abort installation if verification fails; do not silently fall back to execution.
  7. Prefer signed, platform-native packages with clear publisher identity where available.
  8. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  9. Document the files, network endpoints, and permissions used by the installer so users can assess its effects.
  10. Apply equivalent integrity and version-pinning controls to both the Bash and PowerShell installation paths.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into a shell, which creates a classic supply-chain and arbitrary code execution risk. If the remote host, script, transport, or distribution pipeline is compromised, the agent could execute attacker-controlled code on the local system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill for "ANY Quo (OpenPhone) request" and "Whenever a task involves Quo (OpenPhone), use this skill," which is extremely broad for a manifest/markdown-scoped trigger description. It does not provide boundaries, exclusions, or negative examples, so routine mentions of Quo could match unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.