Back to skill

Security audit

The Cat API

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Cat API connector, but its setup instructions include unverified remote installer commands that can execute code on the user's machine.

Review the setup path before installing. Prefer installing the oo CLI through a verifiable package manager or a pinned, checksum-verified installer, and avoid running the remote installer commands from an elevated shell. Expect this skill to use an OOMOL account connection for The Cat API rather than direct local API tokens.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Execution Through Shell Pipelines

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable code from an external server and pass it directly to Bash or PowerShell. The installer is executed without a pinned release, cryptographic checksum, publisher-signature verification, or local inspection.

HTTPS protects the connection in transit and authenticates the endpoint through the certificate infrastructure, but it does not make the remote payload immutable. A compromised hosting account, origin server, release process, or trust chain could change the code executed after this Skill has been reviewed.

Installation of the oo CLI is relevant to the declared connector functionality, and the source uses an OOMOL-associated domain. However, immediate execution of an unverified response exceeds the minimum safe mechanism needed to install the dependency. The current installer contents are not included in the project and therefore could not be audited.

Attack Path

  1. A The Cat API operation fails because the oo CLI is not installed.
  2. The Agent or user follows the first-time setup instructions.
  3. curl or Invoke-RestMethod downloads the installer currently served by cli.oomol.com.
  4. The response is passed directly to Bash or Invoke-Expression.
  5. If the remote payload or delivery infrastructure has been compromised, arbitrary commands execute with the permissions of the invoking account.
  6. The payload could subsequently access local files, credentials available to that account, or install additional components.

Impact Assessment

Successful exploitation provides arbitra ...[truncated 555 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex execution patterns.
  2. Prefer an official operating-system package manager with package-signature verification.
  3. Pin the CLI to a specific reviewed release rather than retrieving a mutable latest installer.
  4. If an installer must be downloaded, save it to disk before execution and provide an opportunity for inspection.
  5. Publish a SHA-256 digest through a separately protected release channel and verify it before execution.
  6. Verify a trusted publisher signature where the platform supports signed artifacts.
  7. Require explicit user approval before installing software or executing any downloaded installer.
  8. Document the installer's required permissions and instruct users not to run it as an administrator or root unless strictly necessary.
  9. Prefer commands equivalent to:
bash
curl -fSLo oo-installer.sh "https://trusted.example/pinned-release/install.sh"
echo "<pinned-sha256>  oo-installer.sh" | sha256sum --check
less oo-installer.sh
bash oo-installer.sh

The URL and digest must correspond to a specific immutable, reviewed release.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill includes a one-line remote install command that fetches a script over the network and pipes it directly to bash. If the remote host, transport, or distribution path is compromised, or if the script changes unexpectedly, this can lead to arbitrary code execution on the user's system with the privileges of the running shell.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says to use this skill for ANY The Cat API request and whenever a task involves The Cat API, which is an unusually broad trigger condition. Broad invocation guidance can cause the agent to activate the skill in marginal contexts and route tasks into shell-based execution paths unnecessarily, increasing the chance of unintended tool use or exposure to other risky instructions in the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.