Back to skill

Security audit

TemplateFox

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for TemplateFox automation, but its setup instructions include unverified remote installer commands that could execute arbitrary code.

Review this skill before installing. It appears intended for legitimate TemplateFox automation, but do not let an agent run the documented curl | bash or PowerShell iex installer automatically; install oo only through a trusted, verifiable method and confirm any TemplateFox write action payload before execution.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62–66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions download mutable scripts from an external server and immediately execute their contents using Bash or PowerShell. Neither command pins a specific installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded code before execution.

Consequently, the effective installer payload can change after the Skill has been reviewed. Compromise of the hosting domain, deployment pipeline, DNS or TLS trust chain could replace the expected installer with arbitrary executable code. A transient server error or unexpected response could also be passed directly to the command interpreter.

The installation behavior is conditional on the oo CLI being unavailable and uses an OOMOL-branded HTTPS domain, but those factors do not establish the integrity of the retrieved payload. Direct remote-script execution also exceeds the normal tool scope declared as Bash(oo *). Although installing the required CLI may be necessary, piping an unverified response into a shell is not the minimum privilege or safest installation method.

The Skill's ordinary network operations through oo connector run are consistent with its declared TemplateFox integration. No evidence was found that it accesses local secrets or covertly exfiltrates information. The confirmed issue is specifically the unverified installer execution channel.

Attack Path

  1. A TemplateFox operation fails because the oo CLI is not installed.
  2. The Agent or user follows the documented first-time setup instructions.

...[truncated 1015 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation commands.
  2. Prefer a trusted operating-system package manager or an official, signed release package.
  3. Pin the installer or package to an explicit version rather than retrieving a mutable latest script.
  4. Download the artifact to disk without executing it automatically.
  5. Publish and verify a SHA-256 checksum obtained through a separately protected channel.
  6. Verify a cryptographic signature tied to a documented publisher identity.
  7. Allow the user or Agent operator to inspect the downloaded script before execution.
  8. Require explicit user approval before installing software or running any installer.
  9. Execute the installer with the least privileged account possible and avoid requesting administrator privileges unless strictly necessary.
  10. Keep installation outside the Skill's normal action workflow; the Skill should ordinarily invoke only the already-installed oo executable permitted by Bash(oo *).
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill instructs the agent to execute a remote install script via curl ... | bash, which is a classic unsafe pattern because it runs network-fetched code without verification, pinning, or integrity checks. In an adversarial or compromised distribution scenario, this could lead to arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Static analysis

No suspicious patterns detected.