Back to skill

Security audit

SmugMug

Security checks for vulnerabilities and agentic risk

Overview

The SmugMug skill is mostly coherent, but its setup instructions include unverified remote installer commands that can execute changing network code on a user's machine.

Review the setup path before installing. Prefer installing the oo CLI through a verified, versioned package or after manually inspecting and verifying the installer, and understand that connecting OOMOL to SmugMug lets the connector read SmugMug account data through your authorized connection.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:77
Finding

Unverified Remote Installer Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 77–81
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions retrieve scripts from an external server and pass their contents directly to Bash or PowerShell. The downloaded payload is not pinned to a specific release and is not verified using a cryptographic checksum or digital signature before execution.

Although installing the oo CLI supports the Skill's declared SmugMug functionality and the download domain is associated with the declared publisher, executing a mutable network response directly is not the minimum privilege or safest installation mechanism necessary. HTTPS protects data in transit but does not prevent malicious execution if the hosting infrastructure, DNS resolution, publishing account, CDN, or installer itself is compromised.

Because the effective installer payload can change after the Skill has been reviewed, the commands create a remote code-execution channel outside the audited project contents. The audit found no evidence that the current remote scripts are malicious; the vulnerability is the absence of an integrity and review boundary before execution.

Attack Path

  1. A user or Agent attempts to use the Skill on a system where the oo CLI is unavailable.
  2. The command fails with oo: command not found.
  3. The Skill directs the user or Agent to run the applicable installation command.
  4. The shell retrieves the current installer from cli.oomol.com.
  5. If the remote script, hosting service, publishing credentials, CDN, or network resolution has been compromised, attacker-controlled content is returned.
  6. Bash or PowerShell immediately executes th ...[truncated 940 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all curl | bash and Invoke-RestMethod | Invoke-Expression installation instructions.
  2. Prefer a trusted platform package manager with a pinned CLI version and verifiable package provenance.
  3. If a standalone installer is required, download it to a local file without executing it:
    • Use a version-specific, immutable artifact URL.
    • Publish and verify a SHA-256 or stronger digest.
    • Verify a detached digital signature against a documented, trusted public key.
    • Abort installation if any integrity check fails.
  4. Allow the user to inspect the downloaded script before execution.
  5. Require explicit user approval before installing software or running any installer.
  6. Run installation with ordinary user privileges whenever possible; do not request administrator or root privileges unless a documented component strictly requires them.
  7. Document the expected files, directories, network destinations, and permission changes made by the installer.
  8. Pin the expected oo CLI version so subsequent changes to the remote installer cannot silently alter reviewed behavior.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a direct network fetch piped into a shell (curl ... | bash), which enables arbitrary code execution from a remote endpoint without prior integrity verification. If the install server, transport, or published script is compromised, a user following the fallback steps could execute attacker-controlled code on their machine.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY SmugMug request" and "Whenever a task involves SmugMug," which is extremely broad and lacks boundaries or exclusion conditions. This can overlap with many ordinary references to SmugMug and does not specify when the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.