Back to skill

Security audit

Scrapfly

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Scrapfly workflow is coherent, but its first-time setup tells users or agents to execute mutable remote installer scripts directly in a shell.

Review this skill before installing. The Scrapfly actions themselves are read-focused and purpose-aligned, but use a safer oo CLI installation path if possible: prefer official documentation, a pinned release, and checksum or signature verification instead of running the provided one-line remote installer commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from external URLs and immediately pass their contents to a command interpreter. Neither command pins a release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded code before execution.

Installing the oo CLI supports the declared Scrapfly functionality, but immediate pipe-to-shell execution is not the minimum privilege or minimum-trust installation method required to achieve that purpose. The effective installer payload is not included in the reviewed project and can change after this Skill has been audited.

The project does not establish that the current remote scripts are malicious. Nevertheless, this pattern creates a remote code-execution channel: compromise of the distribution server, publishing account, DNS path, or another relevant supply-chain component could cause arbitrary attacker-controlled code to execute.

Attack Path

  1. An attacker compromises or gains the ability to modify the installer served from cli.oomol.com, or otherwise causes that trusted URL to return attacker-controlled script content.
  2. The oo command is unavailable, causing a user or agent to follow the documented first-time setup instructions.
  3. curl or irm downloads the modified script.
  4. The shell pipeline forwards the response directly to Bash or PowerShell without integrity verification or review.
  5. The attacker-controlled script executes with all permissions held by the invoking process.
  6. The script can then access available local data, modify user-own ...[truncated 782 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex installation instructions.
  2. Direct users to a versioned release artifact hosted through an authenticated official release channel.
  3. Pin the installer or binary to a specific reviewed version rather than retrieving a mutable latest script.
  4. Publish a SHA-256 digest and, preferably, a cryptographic signature backed by a documented verification key.
  5. Download the artifact to a local file without executing it, then verify its checksum and signature before use.
  6. Allow the user to inspect the installer and require explicit approval before execution.
  7. Prefer a platform package manager with signed packages and version pinning where available.
  8. Run installation with ordinary user privileges. Request elevation only for a narrowly defined operation that demonstrably requires it.
  9. Document the installer’s expected file changes, network destinations, credential handling, and rollback procedure.
  10. If automated installation remains necessary, vendor a reviewed installer into the release process and protect updates with reproducible builds, signed provenance, and release integrity controls.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a classic pipe-to-shell installation command (curl ... | bash) that fetches and executes a remote script without verification. If the remote host, transport, distribution path, or script contents are compromised, the agent or user may execute arbitrary code on the local system with the current user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description uses an expansive activation condition: "Use this skill for ANY Scrapfly request" and "Whenever a task involves Scrapfly." In a markdown skill file, this is a vague trigger because it does not clearly bound when the skill should or should not activate, and it provides no exclusions or negative examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.