Back to skill

Security audit

ScrapingAnt

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ScrapingAnt connector, but its setup instructions can execute unverified remote installer scripts on the user's machine.

Review the setup path before installing. Prefer installing the oo CLI through a verified package or official guide with checksum or signature validation, and do not let an agent run the pipe-to-shell installer automatically. Connect ScrapingAnt only if you intend OOMOL to use your ScrapingAnt account for the listed scraping and extraction actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Executed Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable shell script from https://cli.oomol.com/install.sh and pipes it directly into Bash. The command does not pin a release, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded script before execution.

Consequently, the effective code executed on the host can change after the Skill has been audited. Compromise of the remote service, its DNS or TLS infrastructure, or its release process could turn this installation path into an arbitrary-code-execution channel. Although the instruction is presented as a conditional first-time setup step, executing remote code in this manner exceeds the minimum privileges required merely to document or use the connector.

Attack Path

  1. The oo CLI is absent, causing the documented first-time setup condition to apply.
  2. The user or Agent runs the provided installation command.
  3. curl retrieves the current contents of the mutable remote installer.
  4. The response is passed directly to Bash without integrity or authenticity verification beyond transport-layer TLS.
  5. A compromised or malicious response executes with the privileges of the invoking user.
  6. The payload can read or modify accessible files, steal session credentials, run additional commands, install persistence, or download further payloads.

Impact Assessment

Successful exploitation provides arbitrary command execution with the permissions of the account running Bash. The accessible scope may include user files, environment variables, authentication material, local application data, and any resources available through the user's active s ...[truncated 266 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation pattern.
  • Direct users to a version-pinned release hosted in a verifiable official repository or package manager.
  • Download the installer as a separate file without executing it automatically.
  • Publish and require verification of a cryptographic signature or a checksum obtained through an independently trusted channel.
  • Allow the installer to be inspected before execution.
  • Require explicit user approval before installing software or running any downloaded installer.
  • Run installation with the least-privileged account possible and avoid requesting elevated privileges unless a documented component strictly requires them.
  • Prefer an auditable sequence such as download, signature verification, review, and explicit execution.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installer Executed Through PowerShell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Complete Code Snippet:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The PowerShell instruction retrieves a mutable script with Invoke-RestMethod (irm) and passes the response directly to Invoke-Expression (iex). Invoke-Expression interprets the downloaded text as PowerShell code immediately. No fixed version, cryptographic signature, checksum, or local review step is required.

This design makes the external endpoint part of the executable codebase while allowing its content to change independently of the reviewed Skill. If the endpoint or its delivery chain is compromised, arbitrary PowerShell commands can be supplied and executed on the Windows host. Conditional placement under first-time setup reduces invocation frequency but does not mitigate the integrity risk.

Attack Path

  1. The oo CLI is unavailable on a Windows system.
  2. The user or Agent follows the documented fallback installation command.
  3. Invoke-RestMethod obtains the current remote response from cli.oomol.com.
  4. The pipeline sends that response directly to Invoke-Expression.
  5. A compromised or malicious installer response executes under the invoking Windows user's security context.
  6. The payload can access user-readable data, authentication material, network resources, and other capabilities granted to that account, and can attempt further compromise.

Impact Assessment

Successful exploitation results in arbitrary PowerShell execution with the invoking user's privileges. This may expose local files, environment data, credentials available to the user, connected services, and reachable network resources. Execution by an administrator could permit system-wide changes. The Skill contains no direct ...[truncated 210 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex installation pattern.
  • Provide a version-pinned installer from a verifiable official release location.
  • Download the PowerShell script to disk without invoking it.
  • Require Authenticode signature validation or verification against a securely published cryptographic digest before execution.
  • Permit review of the downloaded script and require explicit user consent before running it.
  • Use a trusted Windows package manager with signed, pinned packages where practical.
  • Execute installation using the least-privileged account and avoid administrator elevation unless it is explicitly justified.
  • Document a secure installation flow that separates retrieval, verification, and execution.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell (curl ... | bash), which executes unreviewed code fetched at runtime. If the hosting site, transport, or distribution path is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY ScrapingAnt request," which is a very broad activation condition and does not define clear boundaries or exclusions. In a manifest file, this can cause unintended invocation whenever ScrapingAnt is merely mentioned, rather than only for specific supported actions or contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.