Back to skill

Security audit

Serpdog

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Serpdog connector wrapper, but its setup guidance includes unverified internet installer scripts that could execute arbitrary local code.

Review this skill before installing. Use it only if you trust OOMOL's connector flow and Serpdog account access, and do not let an agent run the curl|bash or irm|iex setup commands automatically; prefer a verified package manager, pinned release, or manually inspected installer for the oo CLI.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Scripts Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–63
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from cli.oomol.com and immediately execute the returned content using Bash or PowerShell. The commands do not pin a release, verify a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded scripts before execution.

Although installing the oo CLI supports the Skill's declared Serpdog connector functionality, direct remote-to-shell execution is not the minimum privilege necessary to accomplish that installation. HTTPS protects the connection in transit but does not establish that the current server response is the same code reviewed with this Skill. A compromised origin, hosting account, CDN, DNS/control plane, or future installer revision could replace the effective payload after the Skill package has been audited.

The instructions limit installation to a fallback after an oo: command not found error, which reduces invocation frequency but does not mitigate the integrity risk when the fallback is used.

Attack Path

  1. The agent attempts to invoke the oo CLI for a Serpdog request.
  2. The command fails because the CLI is unavailable.
  3. Following the documented fallback, the agent runs the applicable installation command.
  4. Bash or PowerShell retrieves the current response from cli.oomol.com.
  5. The shell executes that response immediately without local verification.
  6. If the remote distribution channel or installer has been compromised or maliciously changed, attacker-controlled commands execute with the privileges of the user or agent process.

Impac

...[truncated 642 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation patterns.
  2. Pin the installer or binary to a specific, reviewed CLI release rather than retrieving a mutable latest-version script.
  3. Download the artifact to a local file without executing it.
  4. Verify the artifact against a checksum published through an independent trusted channel. Prefer a cryptographic release signature with a pinned and authenticated signing key.
  5. Display the selected version, source, verification result, and intended installation changes before requesting explicit user approval.
  6. Execute the verified installer as a separate step with ordinary user privileges. Do not request administrative privileges unless a specific installation operation requires them.
  7. Prefer a trusted platform package manager or signed release package where available.
  8. Keep CLI installation outside automatic Skill execution where possible and instruct the user to complete installation manually.
  9. If script-based installation must remain supported, publish immutable versioned URLs and fail closed when integrity verification cannot be completed.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs use of a remote install command that pipes content fetched over the network directly into a shell. If the install endpoint, transport, or upstream distribution is compromised, this leads to immediate arbitrary code execution on the user's machine with the privileges of the running shell.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for ANY Serpdog request and instead of calling the API directly, which is an overly broad activation rule. That can cause the agent to invoke this skill in situations where a narrower or safer path would be more appropriate, increasing the chance of unintended tool use and unnecessary exposure to connector-side actions or setup guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.