Back to skill

Security audit

Shippo

Security checks for vulnerabilities and agentic risk

Overview

This Shippo skill is coherent, but its setup instructions tell users to execute remote installer scripts directly, which is high-impact and not integrity-checked.

Install only if you trust OOMOL's installer delivery path and are comfortable with one-time setup that may execute mutable remote code on your machine. Prefer manually reviewing the installer or using a verified package or checksum before running it, and confirm all Shippo write payloads before allowing the skill to create account objects.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Scripts Executed Directly by Shells

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The installation instructions download mutable scripts from external URLs and immediately execute them using Bash or PowerShell. They do not pin an installer version, verify a cryptographic checksum or digital signature, or give the user an opportunity to inspect the downloaded content. The Skill therefore delegates its effective installation behavior to infrastructure outside the audited package. A compromise of the OOMOL download domain, hosting environment, publication pipeline, DNS resolution, or another relevant delivery component could replace the installer after this Skill has been reviewed. Installing the required CLI is relevant to the declared Shippo connector functionality, but piping an unverified response directly into a command interpreter exceeds the minimum execution behavior necessary to perform that installation safely. ### Attack Path 1. A Shippo operation fails because the `oo` CLI is not installed. 2. The user or agent follows the first-time setup instructions in `SKILL.md`. 3. `curl` or `Invoke-RestMethod` retrieves the current installer from `cli.oomol.com`. 4. The response is passed directly to Bash or `Invoke-Expression` without integrity or authenticity verification beyond transport security. 5. If the remote script or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the user running the installation. 6. Those commands can access resources available to th ...[truncated 917 chars]
Remediation
View remediation
/install.sh" echo " oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.sh ``` The real implementation should use an official pinned release URL and an independently verifiable signature or checksum. The PowerShell installation process should provide equivalent download, signature verification, inspection, and explicit-execution stages. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remote script directly into bash, which executes unverified code from the network without review or integrity checking. In a security-sensitive agent context, this is dangerous because a compromised host, CDN, or upstream install script could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Shippo request" and "Whenever a task involves Shippo," which is a broad activation condition rather than a narrowly scoped trigger. For a markdown skill file, this can cause unintended invocation because it does not define clear limits, exclusions, or negative examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.