Back to skill

Security audit

Ragie

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Ragie, but its fallback setup tells agents to run unverified remote installer scripts through a shell.

Review the setup instructions before installing. Use this skill only if you are comfortable with Ragie operations through OOMOL and avoid running the remote installer commands unless you have independently verified the official installation source and understand the local changes it will make.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:70
Finding

Unverified Remote Installer Execution Through System Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 70–77
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The setup instructions download mutable scripts from an external server and immediately execute them using bash or PowerShell's Invoke-Expression. Neither command pins a release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded content before execution.

Consequently, the code that is actually executed can change after the Skill has been reviewed. Compromise of the distribution server, its deployment process, DNS or another relevant delivery component could turn an otherwise legitimate installation command into arbitrary local code execution.

This behavior also exceeds the Skill's declared operational restriction of Bash(oo *). Normal functionality only requires invoking an already installed oo client, while these instructions give remotely supplied code access to a general-purpose system shell. The fact that installation is presented only as a fallback reduces invocation frequency but does not remove the execution risk.

The documented connector operations necessarily send user-supplied Ragie requests to the declared OOMOL/Ragie service. The reviewed file does not establish covert credential theft or transmission to an unrelated destination; therefore, no separate sensitive-data exfiltration vulnerability is confirmed from the available evidence.

Attack Path

  1. The agent attempts a documented Ragie operation and receives an `o ...[truncated 1535 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation patterns.
  2. Direct users to a versioned release artifact from the vendor's official release repository.
  3. Pin an explicit CLI version rather than downloading a mutable latest installer.
  4. Download the artifact to a local file without executing it.
  5. Verify a vendor-provided cryptographic signature or a SHA-256 checksum obtained through a trusted, independently authenticated channel.
  6. Display the artifact source, pinned version, expected digest, installation effect, and destination before proceeding.
  7. Require explicit user approval before executing any installation step.
  8. Install with ordinary user privileges unless elevated privileges are strictly necessary and separately approved.
  9. Apply equivalent controls to the Windows workflow; do not use Invoke-Expression on a network response.
  10. Prefer a documented package-manager installation where package signatures and repository trust are enforced.
  11. Keep installation outside the Skill's normal execution flow where possible, preserving the declared Bash(oo *) least-privilege boundary.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software via curl ... | bash, which executes a remote script directly without verification. If the remote host, transport, distribution pipeline, or script contents are compromised, this can result in arbitrary code execution on the user's system.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says to use this skill for "ANY Ragie request" and "whenever a task involves Ragie," which is broad enough to trigger the skill on simple mentions or low-risk informational tasks. In an agent setting, this can cause unintended invocation of a capability that includes write and destructive actions, increasing the chance of unnecessary data access or state-changing operations being brought into scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.