Back to skill

Security audit

Cert Spotter

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Cert Spotter through OOMOL, but its setup instructions include unsafe one-line remote script execution for installing the CLI.

Review the setup section carefully before installing. Prefer installing the oo CLI through a verified, version-pinned method with signatures or checksums, and only allow write or delete Cert Spotter actions after confirming the exact target and payload.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command retrieves a mutable script from an external URL and pipes it directly into Bash. The downloaded content is not pinned to a reviewed version and is not validated using a cryptographic signature or a pinned checksum before execution.

HTTPS provides transport protection but does not establish that the script remains identical to the version reviewed during this audit. Compromise of the hosting service, its deployment pipeline, associated accounts, or other upstream infrastructure could replace the installer. The substituted payload would then execute immediately without an opportunity for inspection.

Installing the CLI may be necessary when it is absent, but executing unverified network content directly is not the minimum-privilege installation method required by the Skill's Cert Spotter functionality.

Attack Path

  1. The oo CLI is unavailable and an authentication or connection operation requires it.
  2. The agent or user follows the documented first-time setup command.
  3. An attacker who controls or compromises the remote installer endpoint or its publishing pipeline substitutes malicious shell content.
  4. curl downloads the substituted content.
  5. The shell pipeline passes the content directly to Bash without signature, checksum, version, or source verification.
  6. Bash executes the attacker's commands with all privileges available to the invoking user.

Impact Assessment

A successful exploit provides arbitrary command execution under the invoking user's account. The payload could read or modify accessible files, collect local credentials and tokens, alter application configuration, install additi ...[truncated 345 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash installation instruction.
  • Prefer an official operating-system package manager or a pinned release artifact from a verifiable official repository.
  • Pin the CLI to an explicitly reviewed version rather than retrieving a mutable latest installer.
  • Download the artifact to disk without executing it automatically.
  • Verify a publisher-provided cryptographic signature or a securely distributed, version-specific SHA-256 digest before installation.
  • Display or otherwise make the downloaded installer available for inspection before execution.
  • Run installation with ordinary user privileges wherever possible and request elevation only for narrowly defined installation steps.
  • Document the expected download origin, version, checksum, files installed, and required permissions.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The command uses Invoke-RestMethod through its irm alias to retrieve PowerShell source code from a mutable external endpoint and passes it directly to Invoke-Expression through iex. Invoke-Expression interprets the response as code immediately.

No release version, Authenticode signature, cryptographic digest, or other integrity constraint is checked. Consequently, the effective code executed by the Skill can change after review. HTTPS alone does not mitigate compromise of the legitimate server, publishing credentials, build pipeline, or hosting infrastructure.

CLI installation can support the declared functionality, but executing arbitrary network responses with Invoke-Expression exceeds the minimum mechanism necessary to install a client securely.

Attack Path

  1. The oo CLI is missing on a Windows system.
  2. The agent or user follows the documented PowerShell setup instruction.
  3. An attacker compromises or gains control over the installer endpoint or its release process.
  4. Invoke-RestMethod retrieves attacker-controlled PowerShell source.
  5. The response is passed directly to Invoke-Expression without validation or review.
  6. The malicious PowerShell commands execute in the current user's security context.

Impact Assessment

Exploitation permits arbitrary PowerShell execution with the invoking process's privileges. An attacker could access files and credentials available to the user, modify local configuration, download further payloads, manipulate security settings within the user's authority, or attempt persistence. Execution from an elevated PowerShell session would expose administrator-lev ...[truncated 168 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm | iex pattern entirely.
  • Distribute the CLI through a trusted Windows package mechanism or provide a version-pinned installer.
  • Download the installer as a file rather than evaluating the HTTP response as PowerShell code.
  • Require successful Authenticode signature verification against the expected publisher before execution.
  • Additionally verify a securely published, version-specific SHA-256 checksum.
  • Present the artifact and intended installation effects for inspection and user approval.
  • Avoid administrator execution unless a specific installation operation requires it, and isolate that elevated operation.
  • Document the pinned version, expected signer identity, checksum, installation destination, and required permissions.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to execute a remote installation script via curl ... | bash, which is a classic unsafe pattern because it blindly downloads and executes code from the network without verification, pinning, or integrity checking. In this skill context, that risk is amplified because the document operationalizes shell execution for an external connector workflow, so a user or agent following the fallback steps could execute attacker-controlled code if the endpoint, delivery chain, or transport assumptions are compromised.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Static analysis

No suspicious patterns detected.