Back to skill

Security audit

Scopus

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Scopus connector, but its first-time setup tells users to run unverified remote installer scripts directly in a shell.

Review the first-time setup before installing. Prefer installing the oo CLI through a trusted, version-pinned package or verified download, and avoid running pipe-to-shell installer commands unless you trust the publisher and understand the local system changes. Once oo is already installed and connected, the Scopus actions themselves appear limited to read-only connector use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions pipe scripts retrieved from external URLs directly into Bash or PowerShell. The content is executed without pinning an immutable release, verifying a cryptographic digest or publisher signature, or providing an opportunity to inspect the downloaded file.

HTTPS protects the connection in transit but does not establish that the mutable script remains safe after this Skill has been reviewed. Compromise of the distribution server, hosting account, DNS path, signing infrastructure, or upstream build process could cause arbitrary attacker-controlled commands to be returned and immediately executed.

Installing the CLI is conditional on oo being unavailable, but remote script execution is not required for ordinary read-only Scopus operations when a trusted CLI installation already exists. The installation method therefore introduces privileges and supply-chain exposure beyond those needed to issue Scopus queries.

Attack Path

  1. A user requests a Scopus operation.
  2. The oo command is unavailable, causing the documented first-time setup path to be followed.
  3. The agent or user runs one of the installation commands.
  4. The external endpoint, or infrastructure controlling its response, supplies modified script content.
  5. Bash or PowerShell executes that content immediately under the invoking user's account.
  6. The payload can perform arbitrary actions available to that account before proceeding with, imitating, or abandoning installation.

Impact Assessment

Successful exploitation grants arbitrary comman ...[truncated 555 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove both direct execution patterns: curl | bash and irm | iex.
  • Prefer a trusted platform package manager and pin an exact CLI version.
  • If direct download is unavoidable, use a version-specific immutable artifact URL.
  • Download the artifact to a local file without executing it.
  • Verify a pinned SHA-256 digest and a cryptographic signature tied to a documented publisher key.
  • Abort installation on any verification failure.
  • Allow the script or package contents to be reviewed before execution.
  • Run installation without administrative privileges unless a specific installation step demonstrably requires them.
  • Keep installation separate from normal Skill execution and require explicit user approval before installing software.
  • Document the files, permissions, and system changes made by the installer.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install missing tooling via curl ... | bash, which downloads and immediately executes remote code without integrity verification. Because the skill content is adversarial input and the fallback is embedded directly in operational instructions, a failure path could lead an agent or user to run untrusted installer code, resulting in arbitrary code execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY Scopus request" and "Whenever a task involves Scopus," which is a very broad activation condition in a manifest file. It does not define boundaries, exclusions, or negative examples, so ordinary mentions of Scopus could unintentionally trigger the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.