Back to skill

Security audit

SearchApi

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent SearchApi connector, but its first-time setup tells users to execute remote installer scripts directly, which needs review before installation.

Before installing, use a safer oo CLI installation path if available: prefer official package-manager or versioned release instructions, verify checksums or signatures where provided, and do not run the remote installer command automatically in a sensitive workspace. Once installed, the SearchApi actions themselves appear limited to the connected account's read/search operations.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions retrieve mutable content from external URLs and pass the responses directly to command interpreters. Neither command saves the installer for inspection nor verifies its version, checksum, or cryptographic signature before execution.

Consequently, the effective code executed by this Skill can change after the package has been reviewed. An attacker who compromises the installer host, its publishing pipeline, the associated deployment credentials, or a relevant network trust dependency could replace the response with arbitrary commands.

Installing the required CLI is related to the declared SearchApi functionality. However, immediate execution of an unpinned and unverified network response is not the minimum privilege or safest mechanism needed to install it. The Windows instruction has the same underlying weakness as the Unix instruction: Invoke-RestMethod retrieves the response and Invoke-Expression immediately evaluates it as PowerShell code.

Attack Path

  1. The oo CLI is absent, and a user or agent follows the documented first-time setup procedure.
  2. An attacker compromises or gains control over the remote installer response, such as through the hosting infrastructure or release pipeline.
  3. The victim executes the documented curl | bash or irm | iex command.
  4. The shell evaluates the attacker-controlled response without prior inspection or integrity verification.
  5. The payload performs arbitrary actions with the permissions of the invoking user.

Impact Assessment

Successful exploitation pro ...[truncated 767 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove direct curl | bash and irm | iex installation pipelines.
  2. Prefer a trusted operating-system package manager or an official, version-pinned release package.
  3. Download the installer or binary without executing it automatically.
  4. Pin an immutable release version rather than using mutable install.sh or install.ps1 endpoints.
  5. Publish and verify a SHA-256 or stronger digest obtained through an independently protected channel.
  6. Verify a cryptographic release signature against a pinned, documented signing key.
  7. Allow the user to inspect the downloaded artifact and display the filesystem, network, and privilege changes it will make.
  8. Require explicit user approval before executing installation code.
  9. Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  10. If an automated installer remains necessary, fail closed when version, checksum, signature, or publisher verification fails.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software by piping a remote script directly into a shell, which executes unverified code from the network without integrity checking or review. In this context, the danger is elevated because the skill is an execution-oriented agent instruction set, so a downstream agent or user may follow the command verbatim, enabling supply-chain compromise or arbitrary code execution if the installer or delivery path is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY SearchApi request" and "Whenever a task involves SearchApi," which is a very broad trigger without clear scope boundaries or negative examples. In a manifest/markdown context, this can overlap with many ordinary tasks that merely mention SearchApi, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.