Back to skill

Security audit

Táve

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fits its Táve read-only connector purpose, but its setup instructions include unverified remote installer commands that users should review carefully before running.

Install only if you are comfortable using OOMOL as the intermediary for Táve data and avoid running the documented curl|bash or irm|iex commands without separately verifying the installer source, integrity, and permissions. The normal connector actions appear read-only, but they can still access contact and studio information from the connected Táve account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unverified Remote Bash Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 57
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation instruction downloads a mutable script from an external URL and pipes it directly into Bash. The script is executed without first saving and inspecting it, pinning it to a reviewed version, or validating a cryptographic checksum or digital signature.

The package does not contain the installer, so its effective behavior cannot be determined from the audited files. If the hosting account, domain, DNS resolution, TLS termination, or release pipeline is compromised, the remote response can be replaced with arbitrary shell commands after this Skill has been reviewed.

Installing the required CLI supports the declared Táve integration, but executing unverified remote content is not the minimum privilege or minimum-risk mechanism needed to install it.

Attack Path

  1. The oo CLI is unavailable and an operator follows the documented first-time setup.
  2. An attacker compromises or otherwise gains control over the installer delivery path.
  3. The attacker modifies install.sh to contain malicious shell commands.
  4. curl retrieves the modified response.
  5. The pipe sends the response directly to Bash without integrity verification or review.
  6. The malicious commands execute with the privileges of the user running the installation command.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. The resulting payload could read or modify user-accessible files, steal locally available credentials or session data, alter shell configuration, install persistence mechanisms, or compromise other accounts and services accessible from the host. If the command is run with elevated p ...[truncated 59 chars]

Remediation
View remediation

Remediation Suggestions

Remove the pipe-to-shell installation command. Distribute the CLI through a trusted operating-system package manager or provide a version-pinned release artifact from an official release channel. Publish a SHA-256 or stronger checksum and a digital signature through an independently protected channel, then require verification before execution.

If a script remains necessary, download it to a local file, verify its signature and expected digest, allow it to be inspected, and execute it only after explicit user approval. Document the files, network access, and privileges required by the installer, and advise users not to run it as an administrator unless a specific operation strictly requires elevation.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote PowerShell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This instruction uses Invoke-RestMethod (irm) to retrieve a mutable PowerShell script and immediately passes its contents to Invoke-Expression (iex). No fixed release version, cryptographic checksum, digital signature validation, or review step is required.

Because the remote installer is not included in the project, its behavior is outside the static audit boundary and can change after review. Compromise of the installer host or its delivery and release infrastructure would allow an attacker to substitute arbitrary PowerShell instructions. Invoke-Expression then evaluates those instructions directly in the current PowerShell context.

Installing the CLI may be necessary for the declared functionality, but direct evaluation of unverified network content exceeds the minimum risk required for installation.

Attack Path

  1. The oo CLI is unavailable on a Windows system.
  2. The operator follows the documented first-time setup command.
  3. An attacker compromises the remote script or its delivery path and replaces the response with malicious PowerShell.
  4. irm retrieves the attacker-controlled content.
  5. The pipeline passes that content directly to iex.
  6. PowerShell executes the payload with the invoking user's privileges.

Impact Assessment

Exploitation allows arbitrary PowerShell execution in the user's security context. An attacker could access user-readable files, collect credentials or tokens available to the process, download additional payloads, modify PowerShell profiles, establish persistence, or access connected services. Execution from an elevated PowerShell session could result in system-wide modification ...[truncated 14 chars]

Remediation
View remediation

Remediation Suggestions

Remove the irm ... | iex pattern. Prefer a trusted package manager or a version-pinned, signed release artifact. Require Authenticode signature verification and validation of a published cryptographic checksum before running any PowerShell installer.

If an installer script must be offered, download it to disk without evaluating it, verify its signer and digest through an independently protected source, permit inspection, and request explicit user approval before execution. The installer should run without administrator privileges unless a narrowly documented operation requires elevation.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell, which prevents inspection of the downloaded content before execution. If the install endpoint, transport, hosting, or upstream release pipeline is compromised, an attacker could achieve arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The phrase "Use this skill for ANY Táve request" is a broad activation rule that lacks clear scope boundaries or exclusion conditions. While "Táve" is somewhat domain-specific, the instruction still ambiguously covers every possible request involving Táve without clarifying when the skill should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.