Back to skill

Security audit

ServerAvatar

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only ServerAvatar connector, but its setup instructions tell agents to run unverified internet installers directly, so users should review it before installing.

Install only if you trust OOMOL and are comfortable with the oo CLI setup. Prefer installing the CLI yourself from a verified source, reviewing the installer first, and confirming the ServerAvatar account connection and scopes before letting the skill query account data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Executed Directly by Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable shell script from an external URL and sends it directly to Bash. The remote payload is executed without first saving it for inspection, pinning a specific release, or validating a cryptographic signature or checksum.

Although HTTPS protects the connection in transit, it does not ensure that the script remains unchanged after the Skill has been audited. A compromise of the remote domain, installer publication pipeline, hosting environment, or authorized publisher account could replace the installer with arbitrary shell commands.

Installing the CLI may be relevant to first-time setup, but arbitrary remote shell execution exceeds the minimum privileges required for the Skill's declared read-only ServerAvatar queries. The CLI should instead be a user-managed prerequisite installed through a verifiable, consent-based process.

Attack Path

  1. The Agent attempts to use the Skill and receives an oo: command not found error.
  2. The Agent follows the first-time setup instruction in SKILL.md.
  3. curl retrieves the current contents of https://cli.oomol.com/install.sh.
  4. The response is streamed immediately to Bash without verification or review.
  5. If the installer source or delivery pipeline has been compromised, attacker-controlled shell commands execute under the current user's privileges.
  6. Those commands can access data available to that user, modify user-owned files and configuration, install additional components, or invoke any other permissions available to the process.

Impact Assessment

Successful exploitation provides arbitrary command execution with the privileges of the user ...[truncated 465 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl | bash installation pattern from Agent-executable instructions.
  • Treat the CLI as a user-installed prerequisite and require explicit user approval before performing any installation.
  • Pin installation instructions to a specific, immutable CLI release rather than a mutable installer URL.
  • Download the installer or release artifact to disk without executing it automatically.
  • Verify a pinned SHA-256 or stronger digest obtained through an independently trusted channel.
  • Prefer a cryptographically signed release and validate the publisher signature before execution.
  • Display the artifact, version, source, requested privileges, and expected filesystem changes to the user before running it.
  • Execute installation with ordinary user privileges unless elevation is demonstrably necessary and separately approved.
  • Prefer a trusted platform package manager with signature verification and version pinning where available.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote PowerShell Installer Executed Through Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

PowerShell's irm alias invokes Invoke-RestMethod to retrieve content from the external URL. The response is piped directly to iex, an alias for Invoke-Expression, which evaluates the downloaded content as PowerShell code.

The instruction does not pin a release, verify an Authenticode signature, validate a checksum, or provide an opportunity to inspect the script before execution. Consequently, the effective code can change after review. HTTPS alone does not protect against compromise of the publisher, hosting account, or release pipeline.

This creates a general-purpose remote code-execution channel broader than the read-only ServerAvatar functionality declared by the Skill.

Attack Path

  1. The Agent encounters an unavailable oo command on a Windows system.
  2. The Agent follows the PowerShell setup instruction from SKILL.md.
  3. Invoke-RestMethod retrieves the current install.ps1 response from the remote server.
  4. The response is passed directly to Invoke-Expression.
  5. A malicious or compromised installer executes arbitrary PowerShell statements in the Agent user's security context.
  6. The payload can read accessible files and environment data, alter user configuration, download further components, or perform other actions permitted to the process.

Impact Assessment

Exploitation yields arbitrary PowerShell execution with the current user's permissions. The reachable scope includes user-accessible files, configuration, process environment data, and credentials or infrastructure metadata available to that account. System-wide effects would depend on whether the process is already elevated or whether the use ...[truncated 106 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex pattern and never evaluate a network response directly.
  • Require explicit user approval before initiating installation.
  • Use a versioned, immutable release artifact from the verified official publisher.
  • Download the installer to a fixed local path before execution.
  • Validate a pinned cryptographic digest and verify the installer's Authenticode signature and expected publisher identity.
  • Reject unsigned installers, invalid signatures, unexpected redirects, and mismatched versions or hashes.
  • Allow the user to inspect the downloaded script and disclose its expected changes and privilege requirements.
  • Run the installer without administrative privileges unless elevation is necessary and explicitly approved.
  • Prefer a trusted Windows package-management mechanism that verifies publisher signatures and supports version pinning.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill recommends piping a remote script directly into a shell (curl ... | bash), which is a classic supply-chain risk. If the install endpoint, transport, hosting, or upstream distribution is compromised, arbitrary code executes immediately on the user's machine without inspection or integrity verification.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger text is unusually broad: it instructs the agent to use this skill for ANY ServerAvatar request and instead of calling the API directly. That can cause over-invocation on loosely related prompts, increasing the chance of unintended connector use, unnecessary credentialed data access, and bypass of more precise tool selection logic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.