Back to skill

Security audit

SecurityTrails

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for using SecurityTrails through OOMOL, but its first-time setup recommends running a mutable remote installer directly in the shell.

Review the first-time setup before installing. Prefer installing the oo CLI through a pinned, verifiable release or official package-manager flow, and avoid running the curl-to-bash or irm-to-iex command unless you trust the OOMOL installer source and accept that it runs local code with your user privileges.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup instructions pipe content retrieved from an external server directly into bash or PowerShell's Invoke-Expression. The downloaded installers are executed without:

  • Pinning an immutable version or release artifact.
  • Verifying a cryptographic signature or checksum.
  • Saving and reviewing the installer before execution.
  • Constraining its filesystem, network, or process privileges.
  • Requiring explicit user approval immediately before execution.

HTTPS protects data in transit but does not establish that the retrieved script is safe. The effective payload can change after the Skill has been reviewed. Compromise of the vendor server, CDN, DNS infrastructure, publishing credentials, or installer pipeline could therefore turn these documented setup commands into arbitrary code execution.

Installing the required CLI is relevant to the Skill's operation, and the instructions only recommend installation after a command-not-found failure. However, immediate execution of mutable remote content exceeds the minimum privileges and assurance necessary to install the dependency safely.

Attack Path

  1. A SecurityTrails action is requested on a system where the oo CLI is unavailable.
  2. The initial oo command fails with oo: command not found.
  3. The user or agent follows the first-time setup instructions in SKILL.md.
  4. The command retrieves the current installer response from cli.oomol.com.
  5. A compromised server or software-distribution pipeline supplies an attacker-controlled script.
  6. The shell executes that response immediately, without integrity verification ...[truncated 1007 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace pipe-to-shell and Invoke-Expression installation with a pinned package-manager release or immutable release artifact.
  2. Pin an explicit oo CLI version rather than retrieving a mutable installer endpoint.
  3. Download the installer or binary to a local file without executing it automatically.
  4. Publish a cryptographic signature and SHA-256 checksum through a separately protected channel.
  5. Verify the signature and pinned checksum before any execution or installation step.
  6. Require explicit user approval before installing software or running a downloaded installer.
  7. Show the exact artifact URL, version, expected signer, checksum, destination paths, and requested permissions.
  8. Execute installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
  9. Document all filesystem, environment, shell-profile, and network changes performed by the installer.
  10. Prefer platform-native package managers that support signed metadata and version pinning.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs the agent to install the CLI by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the host, transport, or script content is compromised, arbitrary code would run immediately on the user's machine with the user's privileges. In this skill context, the danger is increased because the instruction is presented as an automated remediation step for a missing dependency, making unsafe execution more likely.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Static analysis

No suspicious patterns detected.