Back to skill

Security audit

TicketSource

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent TicketSource read-only connector, but its fallback setup tells users to run unverified remote installer scripts directly in a shell.

Review this before installing. The TicketSource actions themselves are read-only and scoped through OOMOL, but do not run the documented installer pipe commands unless you trust the OOMOL CLI distribution path; prefer a signed or checksum-verified installer and run setup only when you intentionally need the oo CLI.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Shell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup procedure downloads a mutable shell script from an external server and pipes it directly into Bash. The downloaded content is not displayed for review, pinned to a version, checked against a cryptographic hash, or verified using a digital signature before execution.

The -f, -s, and -S options affect HTTP failure and output handling but do not establish the integrity or provenance of the script itself. HTTPS protects the connection in transit under normal conditions, but it does not protect against compromise of the hosting service, CDN, DNS or certificate trust path, or the publisher's release infrastructure. It also does not prevent the remote script from changing after this Skill has been audited.

Installation is only presented as a fallback when oo is unavailable, and obtaining a CLI is relevant to the declared connector functionality. However, immediate execution of unverified network content exceeds the minimum privilege necessary to document or install that dependency. The installer receives the full operating-system privileges of the account running the command.

Attack Path

  1. An attacker compromises the installer host, CDN, publishing pipeline, or another trusted delivery component for cli.oomol.com.
  2. The attacker replaces or modifies install.sh with commands that perform unauthorized actions.
  3. A user encounters the documented oo: command not found condition and follows the fallback installation instruction.
  4. curl retrieves the attacker-controlled response and passes it directly to Bash without an integrity check or review step.
  5. Bash executes the payload with the invoking user's privileges.

...[truncated 984 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash execution pattern.
  • Direct users to an official package manager or a version-pinned release artifact from a documented publisher-controlled repository.
  • Publish a cryptographic checksum and preferably a signed checksum or release signature through an independently authenticated channel.
  • Separate download, verification, inspection, and execution into distinct commands. Abort installation if verification fails.
  • Pin the installer or package to a reviewed version rather than downloading a mutable latest script.
  • Document the files, permissions, and commands used by the installer so users can assess its privilege requirements.
  • Avoid running installation as root. If a specific privileged operation is unavoidable, isolate and document that operation rather than elevating the entire installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote PowerShell Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

This setup instruction uses Invoke-RestMethod (irm) to retrieve mutable PowerShell source from an external URL and sends the response directly to Invoke-Expression (iex). Invoke-Expression interprets the response as code in the current PowerShell process.

No package version is pinned, and no Authenticode signature, cryptographic checksum, or other independent integrity control is verified. Consequently, the actual commands executed can change after review of the Skill. HTTPS alone does not establish that the server-side content is benign or immutable.

Installing the required CLI is relevant to the Skill's function, but direct interpretation of an unverified response is not necessary to accomplish installation safely. The downloaded script inherits the permissions and accessible resources of the PowerShell process.

Attack Path

  1. An attacker gains control over the PowerShell installer response through compromise of the host, CDN, deployment pipeline, or another trusted delivery component.
  2. The attacker places arbitrary PowerShell commands in install.ps1.
  3. A Windows user follows the first-time setup instruction after the oo command is not found.
  4. Invoke-RestMethod downloads the modified response.
  5. The pipeline passes the response directly to Invoke-Expression, which executes it without signature or hash verification.
  6. The payload acts with the current user's privileges and can access resources available to that PowerShell session.

Impact Assessment

Successful exploitation permits arbitrary PowerShell execution as the invoking user. This can expose user documents, environment data, stored credentials ...[truncated 424 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the irm | iex pattern with a separately downloaded, version-pinned installer.
  • Require verification of the installer's Authenticode signature and expected publisher before execution.
  • Publish and verify a SHA-256 or stronger checksum through a trusted, independently authenticated release channel.
  • Use a signed MSI or a reputable package manager with package integrity validation where available.
  • Keep download, verification, and execution as separate steps and stop immediately on any verification failure.
  • Run installation without administrator privileges unless a narrowly defined operation genuinely requires elevation.
  • Document expected installation changes and provide uninstall and integrity-verification procedures.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends piping a remotely fetched installer script directly into a shell (curl ... | bash), which executes unverified code from the network with the user's privileges. If the hosting domain, transport chain, or script content is compromised, this can lead to arbitrary code execution on the local system.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY TicketSource request" and "Whenever a task involves TicketSource," which is an unusually broad activation condition for a manifest/markdown file. It does not provide exclusions or narrower constraints, increasing the risk of unintended invocation for casual mentions or loosely related tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.