Back to skill

Security audit

Scrape.do

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for using Scrape.do through OOMOL, but its setup instructions include directly executing remote installer scripts without verification.

Review the first-time setup before installing. Prefer installing the oo CLI through a verified official package or by downloading and inspecting/verifying the installer rather than piping it directly into a shell. During normal use, expect Scrape.do URLs and payloads to be sent through OOMOL's connector service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installation Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58-62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download installation scripts from an external server and immediately execute them through Bash or PowerShell. Neither command pins the installer to an immutable version nor verifies a cryptographic checksum or publisher signature before execution.

As a result, the code actually executed can change after the Skill has been reviewed. A compromise of the hosting service, publishing account, DNS or TLS infrastructure, or installer delivery pipeline could replace the expected installer with arbitrary commands. The curl | bash and irm | iex patterns also prevent users from meaningfully inspecting the downloaded content before it runs.

Installing the CLI may be necessary to use the declared connector functionality, but immediate execution of an unverified remote script is not the minimum privilege or minimum-risk mechanism required to perform that setup.

Attack Path

  1. The oo CLI is absent, causing the documented first-time setup path to apply.
  2. An attacker compromises or gains control over the remote installer or its delivery infrastructure.
  3. The attacker modifies install.sh or install.ps1 to include malicious commands.
  4. A user or agent follows the setup instructions.
  5. The remote content is passed directly to Bash or PowerShell without verification.
  6. The malicious commands execute with all privileges available to the invoking user.

Impact Assessment

Successful exploitation permits arbitrary local command execution under the invoking user's account. Depending on that account's permissions ...[truncated 662 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex instructions.
  2. Prefer a trusted platform package manager with a version-pinned package and documented publisher identity.
  3. If standalone installers are required, download a specific immutable release to a local file rather than executing a mutable URL:
    • Pin an explicit release version.
    • Publish an expected SHA-256 or stronger checksum through a separate trusted channel.
    • Verify the checksum before execution.
    • Verify a cryptographic publisher signature where supported.
  4. Allow the user to inspect the downloaded script before running it.
  5. Require explicit user approval before installing software or executing any installer.
  6. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation; do not automatically invoke sudo or an elevated PowerShell session.
  7. Document the files, directories, network destinations, and permissions used by the installer.
  8. Fail closed if signature or checksum verification does not succeed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remote script directly into bash, which executes unreviewed code fetched over the network. If the install host, transport, or script supply chain is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says to use this skill for "ANY Scrape.do request" and "Whenever a task involves Scrape.do," which is a very broad trigger without boundaries or exclusion cases. That wording does not clearly distinguish when this skill should or should not activate, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.