Back to skill

Security audit

Skyfire

Security checks for vulnerabilities and agentic risk

Overview

The Skyfire connector is coherent, but its setup instructions include executing an unverified downloaded installer, which needs user review before installation.

Review the installer step before using this skill. Prefer installing the oo CLI from a versioned or signed release, or download and inspect the installer before running it. For normal use, confirm any create_token payload carefully because it can create funded or identity-carrying Skyfire tokens.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Scripts Executed Directly by System Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from external URLs and immediately execute their contents with Bash or PowerShell. Neither command pins an installer version, validates a cryptographic checksum or signature, nor provides an inspection step before execution.

Although installing the oo CLI supports the Skill’s declared connector functionality, piping an unverified network response directly into a shell is not the minimum-risk installation method. The effective code executed on a user’s system can change after the Skill has been reviewed.

An attacker who compromises the installer host, its deployment pipeline, the relevant domain, or another part of the network trust chain could replace the installer with arbitrary commands. Those commands would execute with the privileges of the user running the installation.

Attack Path

  1. The oo command is unavailable, causing the user or agent to follow the first-time setup instructions.
  2. Bash or PowerShell requests a mutable installer from cli.oomol.com.
  3. An attacker with control over the installer delivery path supplies a modified response.
  4. The response is passed directly to bash or iex without integrity verification or review.
  5. The attacker-controlled commands execute locally with the invoking user’s privileges.

Impact Assessment

Successful exploitation permits arbitrary code execution in the invoking user’s security context. The resulting scope may include reading or modifying user-accessible files, stealing locally available credentials or session data, installing persistence, executing additional payloads, and makin ...[truncated 284 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace direct curl | bash and irm | iex execution with installation through a trusted operating-system package manager where possible.
  2. Pin the CLI to a specific reviewed release rather than retrieving a mutable generic installer.
  3. Download the installer or release artifact to disk without executing it automatically.
  4. Publish and verify a cryptographic checksum and, preferably, a signature using a key distributed through an independent trusted channel.
  5. Separate download, verification, inspection, and execution into distinct commands.
  6. Require explicit user approval immediately before executing any downloaded installer.
  7. Document whether elevated privileges are needed and instruct users not to run the installer as an administrator or root unless strictly required.
  8. Prefer signed, reproducible release artifacts from the project’s official release repository.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into the shell, which creates a classic supply-chain and remote-code-execution risk. If the install endpoint, transport, or upstream distribution is compromised, arbitrary code could execute immediately on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Skyfire request" and "Whenever a task involves Skyfire," which is an extremely broad activation condition. It does not define boundaries, exclusions, or negative examples, so ordinary mentions of Skyfire could match and trigger the skill unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.