Back to skill

Security audit

RocketReach

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent RocketReach connector wrapper, but its first-time setup tells users to execute remote installer scripts directly in a shell without verification.

Install only if you trust OOMOL's installer source and are comfortable with a setup step that can run remote code locally. Prefer reviewing the installer first or using a signed, version-pinned package if available. Day-to-day RocketReach connector use appears scoped to the oo CLI and the connected account's RocketReach data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Unverified Remote Shell Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction streams a remotely hosted script directly into Bash. The effective executable payload is retrieved at runtime and can change after the Skill has been reviewed. No fixed release version, cryptographic checksum, digital signature, or manual inspection step is required before execution.

The URL belongs to the vendor identified by the Skill, and the instruction is only presented as a fallback when the CLI is unavailable. Nevertheless, direct curl | bash execution creates a supply-chain trust boundary that is unnecessary for ordinary RocketReach search and lookup operations. If the hosting infrastructure, DNS resolution, TLS termination, CDN, or vendor release process is compromised, arbitrary commands can be supplied to the shell.

Attack Path

  1. The oo CLI is absent, causing the documented first-time setup path to apply.
  2. An agent or user executes the provided installation command.
  3. The current contents of https://cli.oomol.com/install.sh are downloaded without version pinning or independent integrity verification.
  4. The response body is immediately interpreted by Bash.
  5. A compromised or malicious response executes arbitrary commands with the privileges of the user running the command.

Impact Assessment

The remote payload receives the full ambient privileges of the invoking shell. Depending on those privileges and the payload, it could read or modify user files, access environment variables and local credentials, install additional software, alter shell configuration, establish persistence, or invoke network services. If run from an elevated shell, the potential impact may extend to system-wide compromis ...[truncated 271 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe downloaded content directly into a shell.
  • Direct users to a version-pinned release from an authenticated official distribution channel.
  • Download the installer to a local file before execution and require explicit user approval.
  • Publish and verify a SHA-256 or stronger checksum over a trusted channel.
  • Prefer cryptographic release signatures and validate the signer against a pinned vendor key.
  • Document the installer's required filesystem and network effects so users can assess its privilege requirements.
  • Run installation without administrative privileges unless a specific, documented component requires elevation.
  • Where available, use a platform package manager with signed metadata and pinned package versions.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:68
Finding

Unverified Remote PowerShell Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell installation instruction retrieves mutable remote content with Invoke-RestMethod (irm) and immediately passes it to Invoke-Expression (iex). This causes the response body to execute as PowerShell code without version pinning, signature validation, checksum verification, or an opportunity to inspect the downloaded file.

Although the source domain corresponds to the stated Skill vendor and this command is limited to first-time setup, the command establishes a remote code-execution channel whose payload can change independently of the audited Skill. Compromise of the remote host or its delivery chain would allow attacker-controlled PowerShell commands to run locally.

Attack Path

  1. A Windows system does not have the oo CLI installed.
  2. The agent or user follows the documented first-time setup instruction.
  3. PowerShell retrieves the current response from https://cli.oomol.com/install.ps1.
  4. The response is passed directly to Invoke-Expression.
  5. If the delivery source or supply chain is compromised, attacker-controlled PowerShell executes under the current user's security context.

Impact Assessment

The retrieved script can exercise the invoking PowerShell process's permissions. It may access user data, environment variables, saved credentials available to the user, PowerShell profiles, startup locations, and network resources. It could also download further payloads or modify local configuration. Execution from an elevated PowerShell session could permit system-wide changes.

These privileges are broader than those required for the Skill's declared RocketReach lookup and search functionality, which o ...[truncated 106 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern.
  • Provide a version-pinned, signed installer or package from an official release channel.
  • Save the installer locally and verify its Authenticode signature and cryptographic hash before execution.
  • Require explicit user confirmation after displaying the verified source, version, signer, and expected system changes.
  • Execute with standard-user permissions by default and request elevation only for narrowly documented operations.
  • Prefer a package manager that validates signed repository metadata and package integrity.
  • Maintain reproducible release artifacts and publish checksums through a channel independent of the installer host.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a code-execution primitive controlled by an external endpoint; if the install script, transport, hosting, or upstream distribution is compromised, arbitrary commands could run on the user's machine. The risk is increased because the content is embedded as setup guidance inside an agent skill, which may normalize or automate unsafe execution.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY RocketReach request" and "Whenever a task involves RocketReach," which is a broad activation condition without exclusions or negative examples. This can cause unintended invocation for loosely related mentions of RocketReach rather than clearly scoped actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.