Back to skill

Security audit

Supadata

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Supadata connector, but its setup instructions tell users or agents to run unverified remote installer scripts, which is high-impact enough to require review.

Install only if you already trust OOMOL's oo CLI distribution path or are willing to verify the installer yourself. Prefer installing oo through a pinned, signed, or otherwise verifiable release channel before using the skill, and do not let an agent automatically run the curl-to-bash or irm-to-iex setup commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Unverified Remote Installation Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64–68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from an external server and execute them immediately through Bash or PowerShell. The commands do not pin a script version, verify a cryptographic signature or checksum, save the content for inspection, or constrain the installer in a sandbox.

The domains are consistent with the declared OOMOL provider, and installation is presented as a fallback only when oo is unavailable. Nevertheless, the effective code is controlled by the remote endpoint and can change after this Skill has been reviewed. A compromise of the domain, server, DNS path, TLS termination, deployment process, or installer publishing account could therefore turn the documented setup command into an arbitrary-code execution channel.

Installing software also exceeds the minimum privileges required for the Skill's ordinary operation, which only needs permission to invoke an already installed oo CLI using the restricted Bash(oo *) tool declaration. Installation should consequently be treated as a separate, explicitly approved administrative action rather than an automatic Skill fallback.

Attack Path

  1. The oo command is absent, causing an agent or user to consult the first-time setup instructions.
  2. An attacker compromises or otherwise gains control over the remote installation script or its delivery infrastructure.
  3. The victim executes the documented pipe-to-shell command.
  4. Bash or PowerShell runs the attacker-controlled response immediately, without integrity verification or prior inspection.
  5. The payload per ...[truncated 958 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove direct curl | bash and irm | iex installation flows.
  2. Direct users to a version-pinned release artifact from the official release channel.
  3. Publish and require verification of a cryptographic signature or a checksum obtained through an independently authenticated channel.
  4. Download the artifact to disk, verify it, and allow inspection before execution.
  5. Require explicit user approval before installing software; do not let the agent install it automatically after a command failure.
  6. Prefer a trusted platform package manager with package signing and fixed version constraints where available.
  7. Run installation with ordinary user privileges unless elevated privileges are demonstrably required, and document every filesystem or configuration change.
  8. Keep normal Skill execution limited to the declared oo command scope and provide a clear failure message when the CLI is unavailable.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remote script directly from the network without prior verification. If the install endpoint, transport path, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use this skill for "ANY Supadata request," which is extremely broad and lacks boundaries or exclusion conditions. That wording can overlap with many normal requests involving Supadata and does not specify narrower trigger phrases or when not to invoke the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.