T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:68- Finding
Unverified Remote Shell Script Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a SwaggerHub read connector, but its setup and tool permissions allow more local and account-level authority than the stated read-only purpose needs.
Review before installing. Use it only if you trust OOMOL and the oo CLI, prefer installing the CLI through a verifiable official package or reviewed installer, and confirm the agent only runs listed read actions against SwaggerHub unless you explicitly approve anything broader.
SKILL.md:68Unverified Remote Shell Script Execution
SKILL.md:72Unverified Remote PowerShell Script Execution
SKILL.md:4Overbroad Wildcard Permission for the OOMOL CLI
The skill instructs users to install software via a remote script piped directly to the shell (curl ... | bash), which is a classic supply-chain and arbitrary code execution risk. If the install endpoint, DNS, CDN, or TLS trust chain is compromised, or if the content changes unexpectedly, executing the command can run attacker-controlled code on the host.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The manifest and description claim this skill is for 'searching and reading data', but the body defines a generic mechanism to invoke any SwaggerHub action and explicitly discusses write/destructive operations. This mismatch can mislead users or higher-level policy systems into treating the skill as read-only when its execution path may permit state-changing requests, creating authorization and consent risks.
The trigger phrase instructing use for 'ANY SwaggerHub request' is overly broad and can cause the skill to be selected for tasks beyond its stated safe scope. In combination with the generic 'run any action' pattern, this increases the chance that sensitive or state-changing operations are routed through the skill without sufficient review.
No suspicious patterns detected.