Back to skill

Security audit

Superchat

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Superchat connector, but its first-time setup tells users to execute a remotely fetched installer directly in a shell.

Review the setup instructions before installing. Prefer installing the oo CLI from verified official release artifacts or a trusted package manager, and avoid running curl-to-bash or irm-to-iex commands unless you have independently verified the installer source and integrity. For normal use, confirm any message-sending or contact-changing payload before allowing the action to run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:65
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 65–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from cli.oomol.com and pass their contents directly to a command interpreter. Neither installation path pins a release version, validates a cryptographic checksum or publisher signature, nor gives the user an opportunity to inspect the downloaded file before execution.

HTTPS protects the connection in transit but does not establish that the delivered script is immutable or safe. Compromise of the hosting domain, publishing credentials, web infrastructure, DNS resolution, or installer release process could cause arbitrary attacker-controlled commands to execute. The effective payload can also change after the Skill itself has been reviewed.

Installing the CLI may be relevant when oo is unavailable, but immediate remote execution is not the minimum privilege or minimum-risk mechanism required to install it. The Skill’s normal connector operations only require invoking an already installed oo command.

Attack Path

  1. A Superchat operation fails because the oo CLI is not installed.
  2. The Agent or user follows the documented first-time setup fallback.
  3. The shell or PowerShell retrieves the current installer from cli.oomol.com.
  4. A compromised or maliciously replaced response is supplied by the remote distribution infrastructure.
  5. bash or iex executes the response immediately without integrity validation or review.
  6. The payload performs arbitrary actions with the privileges and environment of the invoking Agent or user.

Impact Assessment

Successful exploitat ...[truncated 648 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove both direct execution pipelines (curl | bash and irm | iex).
  • Prefer an official operating-system package manager or a verified publisher repository.
  • Pin installation instructions to a specific CLI release rather than a mutable generic installer URL.
  • Download the installer or release artifact to a local file before execution.
  • Publish a cryptographic checksum or digital signature through a separately trusted channel and verify it locally.
  • Fail closed if checksum or signature verification does not succeed.
  • Display the source, version, destination, and expected changes, then obtain explicit user approval before installation.
  • Run installation with ordinary user privileges unless a specific operation demonstrably requires elevated access.
  • Document the files, network endpoints, and configuration changes made by the installer.
  • Keep installation outside automatic Skill execution; if oo is missing, provide safe manual setup guidance rather than executing a remote installer.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the endpoint, transport, DNS, or hosting account is compromised, arbitrary code will run on the user's machine with the agent's privileges.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Superchat request" and "Whenever a task involves Superchat," which is a very broad activation condition without boundaries or exclusion examples. This can overlap with many ordinary requests mentioning Superchat and does not clearly specify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.