Back to skill

Security audit

RenderForm

Security checks for vulnerabilities and agentic risk

Overview

The skill’s RenderForm integration is coherent, but its first-time setup tells users to execute a live remote installer directly in the shell without integrity checks.

Install only if you are comfortable with OOMOL as the CLI provider. Prefer installing the oo CLI through a reviewed or package-manager path, or download and inspect/verify the installer before running it. Be aware that RenderForm actions may use your connected account and credits.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote Installer Scripts Executed Directly by Shell Interpreters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

Both installation commands retrieve scripts from cli.oomol.com and immediately execute the received content with Bash or PowerShell. The instructions do not pin a release, verify a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded script before execution.

Consequently, the effective code executed by the Skill can change after the package has been audited. HTTPS protects the connection in transit but does not mitigate compromise of the distribution server, DNS or certificate infrastructure, publishing account, or installer build pipeline. The PowerShell command has the same security properties as the curl | bash pattern because Invoke-Expression evaluates the retrieved response as code.

Installing the required CLI may support the declared RenderForm integration, but immediate execution of mutable remote content exceeds the minimum mechanism necessary to perform that installation.

Attack Path

  1. An attempted oo command fails because the CLI is unavailable.
  2. The Skill directs the user or Agent to run one of the first-time installation commands.
  3. The command contacts cli.oomol.com and retrieves the current installer without version or integrity verification.
  4. If the hosting service, publishing pipeline, domain, or installer content has been compromised, an attacker returns a modified script.
  5. Bash or PowerShell immediately executes the attacker-controlled response with the privileges of the invoking user.
  6. The payload can access resources available to that account and may install additio ...[truncated 889 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct download-to-interpreter pipelines.
  2. Distribute the CLI through a trusted package manager or provide a pinned release artifact from an immutable release URL.
  3. Download the installer or binary to disk without executing it automatically.
  4. Publish and verify a cryptographic checksum or signature using a trusted, separately distributed verification key.
  5. Fail closed if integrity or signature verification fails.
  6. Allow the user to inspect the resolved artifact and require explicit approval before execution.
  7. Run installation with ordinary user privileges unless a specific installation step demonstrably requires elevation.
  8. Document the files, directories, and configuration that the installer will modify.
  9. Where possible, avoid installation entirely by requiring the user to install the CLI independently before enabling the Skill.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent/operator to install software by piping a remotely fetched script directly into bash, which is a well-known unsafe pattern because it executes unverified code from the network without integrity checking, pinning, or review. In this skill context, the risk is heightened because the installation step is embedded as operational guidance for handling failures, making it more likely to be followed automatically or semi-automatically in a trusted workflow.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Static analysis

No suspicious patterns detected.