Back to skill

Security audit

Spider Cloud

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned for Spider Cloud, but its setup instructions include unsafe remote installer commands that execute downloaded code directly.

Review this before installing. The Spider Cloud connector behavior is coherent, but avoid running the documented curl | bash or irm | iex installer blindly; prefer an official, version-pinned installer or package manager path with checksum or signature verification, and only run setup steps after explicit approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions pipe a remotely downloaded, mutable shell script directly into Bash. The command does not pin an immutable release, verify a cryptographic checksum or publisher signature, or provide an opportunity to inspect the downloaded content before execution.

HTTPS protects the connection in transit under normal conditions, but it does not establish that every future version of the remote installer is safe. Compromise of the hosting service, publishing account, DNS infrastructure, or installer-generation pipeline could cause arbitrary attacker-controlled commands to execute when the setup instruction is followed.

Installing the required CLI is related to the Skill's declared functionality. However, executing an unverified remote response directly in a shell exceeds the minimum trust and execution privileges necessary to perform that installation.

Attack Path

  1. The oo command is unavailable, causing the Agent or user to follow the first-time setup instructions.
  2. An attacker compromises or gains control over https://cli.oomol.com/install.sh or its delivery infrastructure.
  3. The attacker replaces or modifies the installer response with malicious shell commands.
  4. curl retrieves the attacker-controlled response.
  5. The pipe passes the response directly to Bash without integrity verification or review.
  6. Bash executes the payload with the privileges of the user running the command.

Impact Assessment

A malicious installer can execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the surrounding environment, it could read or modify accessible files, steal environment credentials or ap ...[truncated 210 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation pattern.
  • Prefer a signed operating-system package repository or a verified official package manager.
  • Pin installation instructions to a specific immutable CLI version.
  • Download the installer or release artifact to a local file without executing it.
  • Verify the artifact using a hardcoded SHA-256 digest obtained through a separate trusted release channel.
  • Where supported, verify a publisher signature whose public key is independently distributed and pinned.
  • Display the source, version, destination paths, and requested permissions before installation.
  • Require explicit user approval before executing the verified installer.
  • Run installation with ordinary user privileges unless a documented installation step strictly requires elevation.
  • Fail closed if signature or checksum validation does not succeed.

A safer workflow is: download a pinned release artifact, verify its signature and checksum, inspect or unpack it into a controlled location, and only then execute or install it after user confirmation.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote PowerShell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup instruction retrieves a mutable PowerShell script with Invoke-RestMethod (irm) and immediately evaluates the response using Invoke-Expression (iex). This converts remote response content directly into executable PowerShell code.

The instruction does not pin an immutable release, verify an Authenticode signature or cryptographic digest, or save the script for review before execution. Consequently, control of the remote endpoint or delivery infrastructure provides an immediate code-execution channel. HTTPS alone does not mitigate compromise of the legitimate server, publishing credentials, DNS infrastructure, or upstream deployment pipeline.

Installing the CLI supports the declared Skill functionality, but evaluating an unverified network response is not necessary to achieve that purpose and violates least-trust installation practices.

Attack Path

  1. The oo command is unavailable on a Windows system.
  2. The Agent or user follows the documented PowerShell setup instruction.
  3. An attacker compromises or controls the installer endpoint or its delivery infrastructure.
  4. irm retrieves malicious PowerShell content from the endpoint.
  5. The pipeline sends the response directly to iex.
  6. iex evaluates the response in the current PowerShell session with the invoking user's privileges.

Impact Assessment

Successful exploitation permits arbitrary PowerShell execution under the current user's security context. The payload could access user-readable files, collect environment secrets and application credentials, change PowerShell profiles or local configuration, modify tools, establish persistence, or retrieve additional mal ...[truncated 135 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex execution pattern.
  • Distribute the CLI through a signed and reputable Windows package mechanism where possible.
  • Pin the CLI to a specific immutable release.
  • Download the PowerShell script or binary to disk without evaluating it.
  • Validate a pinned SHA-256 checksum and verify the publisher's Authenticode signature before execution.
  • Reject unsigned artifacts, invalid signatures, unexpected publishers, and digest mismatches.
  • Present the artifact version, source, installation paths, and requested privileges to the user.
  • Require explicit user approval after successful validation and before execution.
  • Avoid administrator privileges unless a specific, documented installation operation requires them.
  • Prefer installing a signed binary package over executing a general-purpose remote PowerShell script.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into bash, which is a classic supply-chain and arbitrary code execution risk. If the remote host, transport, or install script is compromised, the user may execute attacker-controlled code immediately with their shell privileges.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY Spider Cloud request" and "Whenever a task involves Spider Cloud," which is an extremely broad activation condition. It does not provide constraints or negative examples to clarify when the skill should not be invoked, increasing the chance of accidental triggering.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.