Back to skill

Security audit

Signaturely

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Signaturely folders, but it includes an unverified remote installer command and grants broad oo CLI command authority beyond the listed Signaturely actions.

Review this skill before installing. It appears intended for legitimate Signaturely folder management, but avoid letting an agent run the remote installer blindly; prefer an official, reviewable, version-pinned install path if available. Also be aware that the skill's oo CLI permission is broader than the listed Signaturely actions, so use it only in an environment where that wider OOMOL CLI access is acceptable.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:54
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions retrieve mutable scripts from external URLs and pass their contents directly to command interpreters. The Bash command pipes the HTTP response into bash, while the PowerShell command passes it to Invoke-Expression.

Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded payload before execution. HTTPS protects the connection in transit but does not establish payload immutability or protect against compromise of the hosting infrastructure, publishing account, DNS configuration, or installer build pipeline.

Installing the required CLI is related to first-time setup, but immediate execution of an unverified remote response exceeds the minimum mechanism necessary. A separately downloaded and cryptographically verified installer would provide the same functionality with materially lower risk.

Attack Path

  1. An attacker compromises the installer host, deployment pipeline, publishing credentials, DNS resolution, or another part of the remote distribution chain.
  2. The attacker modifies install.sh or install.ps1 to include malicious commands.
  3. The oo command is unavailable, causing the documented first-time setup path to be used.
  4. The shell retrieves the attacker-controlled response.
  5. The pipe to bash or iex executes the response immediately without integrit ...[truncated 568 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all curl | bash and irm | iex installation instructions.
  • Direct users to a version-pinned release hosted through an authenticated official release channel.
  • Download the installer to a local file without executing it automatically.
  • Publish and require verification of a SHA-256 or stronger checksum over a secure, independently authenticated channel.
  • Prefer cryptographic release signatures and require verification against a documented, pinned signing key.
  • Use a trusted operating-system package manager where packages and repository metadata are signed.
  • Display the exact installer version and source to the user and require explicit approval before execution.
  • Run installation without administrative privileges unless a specific installation step demonstrably requires elevation.
  • Document how users can inspect the downloaded installer before running it.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:5
Finding

Overbroad Wildcard Authorization for the OOMOL CLI

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Excessive tool authorization and violation of least privilege
Risk Level: Medium

Vulnerable Code:

yaml
allowed-tools: [Bash(oo *)]

Technical Analysis

The declared functionality only requires schema inspection and action execution for the signaturely connector. However, the wildcard authorization permits every command beginning with oo, rather than restricting execution to the required connector, subcommands, and actions.

This creates a broader command-execution boundary than the Skill's stated purpose requires. Although the documented examples use the Signaturely connector, the authorization rule itself does not enforce that limitation. Any additional commands exposed by the installed oo CLI—and any other services available through the authenticated OOMOL account—may fall within the allowed pattern.

The Skill does include confirmation requirements for documented write operations, but those textual requirements do not technically constrain the broad wildcard permission.

Attack Path

  1. The Skill is loaded with permission to execute any command matching oo *.
  2. Malicious or misleading task content influences the Agent's command construction, or the Agent constructs an incorrect command.
  3. The resulting command references an unintended connector, action, or other oo CLI capability.
  4. The wildcard authorization accepts the command because it only checks the oo prefix.
  5. The command accesses or changes resources beyond the declared Signaturely folder-management scope, subject to the permissions of the authenticated OOMOL account.

Impact Assessment

The accessible scope depends on the capabilities of the installed oo CLI and the services connected to the user's OOMOL account. Potential impact includes unauthorized reads, state-changing operations, disclosure of data returned by unrelated conne ...[truncated 238 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace Bash(oo *) with the narrowest supported command patterns.
  • Permit only the required schema and execution forms for the signaturely connector.
  • Enforce an allowlist containing only create_folder, get_folder, list_folders, and rename_folder.
  • Reject attempts to select another connector or invoke unrelated oo subcommands.
  • Preserve explicit user confirmation before create_folder and rename_folder.
  • Validate action payloads against the retrieved schema and avoid constructing commands through unsafe string interpolation.
  • If the permission system cannot express sufficiently narrow patterns, use a dedicated wrapper that validates the connector, action name, and arguments before invoking oo.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs users to install software by piping a remote script directly into a shell (curl ... | bash). This creates a supply-chain and remote-code-execution risk because any compromise of the hosting domain, CDN, TLS termination, or installer script would execute arbitrary commands on the user's machine without review. In this skill context, the risk is heightened because the installation command is embedded as a troubleshooting step that an agent may surface during operational use.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Static analysis

No suspicious patterns detected.