Back to skill

Security audit

SerpApi

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a straightforward SerpApi connector, but its setup instructions tell users or agents to run unverified remote installer scripts directly.

Review this before installing. The search actions themselves are read-only, but do not run the listed installer commands automatically. Prefer an already installed trusted `oo` CLI, a package-managed install, or a downloaded installer with a verified checksum or signature, and approve any authentication or connection steps yourself.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57–61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions pipe scripts retrieved from mutable external URLs directly into a local command interpreter. Neither command pins a specific installer version nor verifies a cryptographic signature or published checksum before execution.

Consequently, the code reviewed in this Skill does not define the code that will ultimately run. The effective payload may change at any time after the Skill has been audited. Although the URLs appear to belong to the declared OOMOL service, domain ownership alone does not establish the integrity of every future response. Compromise of the hosting infrastructure, release pipeline, DNS resolution, or applicable TLS trust chain could substitute arbitrary commands.

Direct remote execution is not necessary for the Skill's declared SerpApi search functionality. Installing a required CLI can be legitimate, but doing so through an unverified pipe-to-shell mechanism grants the installer broader local execution privileges than are required merely to submit search requests.

No evidence in the audited file confirms that the current remote installers are malicious. The vulnerability is the absence of a stable, independently verifiable trust boundary before execution.

Attack Path

  1. The oo command is unavailable, causing the documented first-time setup condition to apply.
  2. A user or agent follows the installation instructions in SKILL.md.
  3. An attacker compromises or gains control over the installer endpoint, its deployment pipeline, or another relevant delivery dependency.
  4. The endpoint returns a modif ...[truncated 1104 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct execution patterns:
    • Do not pipe curl output into bash.
    • Do not pipe Invoke-RestMethod output into Invoke-Expression.
  2. Prefer an official, version-pinned package distributed through a trusted package manager with integrity and provenance controls.
  3. If a standalone installer is unavoidable:
    • Download it to a local file without executing it.
    • Pin a specific release version and immutable release URL.
    • Publish its expected SHA-256 or stronger digest through an independently protected channel.
    • Verify the digest before execution and abort on any mismatch.
    • Prefer cryptographic signature verification using a pinned, documented signing key.
    • Allow the user to inspect and explicitly approve the downloaded script.
  4. Run installation with ordinary user privileges unless a narrowly defined operation explicitly requires elevation. Do not recommend running the entire installer as root or Administrator.
  5. Document the files, commands, network destinations, and configuration changes performed by the installer.
  6. In automated agent workflows, stop and request explicit user approval before downloading or executing installation code.
  7. Pin the CLI version used by the Skill and establish a controlled upgrade process so later installer changes require separate review.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill embeds a one-line remote script execution pattern (curl ... | bash) for first-time setup. If followed by an agent or user, this executes code fetched over the network without prior verification, creating a supply-chain and remote code execution risk if the host, transport, or distributed script is compromised.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is excessively broad: it instructs the agent to use this skill for ANY SerpApi request and instead of calling the API directly. That can cause unintended activation in loosely related tasks, increasing the chance the agent executes networked searches or setup flows without sufficiently narrowing user intent or considering safer alternatives.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.