Back to skill

Security audit

timelink

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a Timelink read-only connector, but its setup guidance tells users to execute unverified remote installer scripts.

Install only if you are comfortable with OOMOL as an intermediary for Timelink access. Avoid running the documented curl-to-bash or irm-to-iex commands directly; prefer an official, versioned, signed, or checksum-verified installer and review any setup steps before executing them. Treat account connection and CLI login as persistent changes to your environment.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:68
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The first-time setup instructions pipe a remotely downloaded installation script directly into Bash. The remote resource is mutable and is neither version-pinned nor checked against a cryptographic checksum or signature before execution. Consequently, the effective code executed by the Skill can change after the package has been reviewed.

Installing the required CLI may be necessary when it is absent, but immediate execution of unverified network content exceeds the minimum safe setup procedure. The audit found no evidence that the referenced domain is intentionally malicious; nevertheless, this delivery pattern creates a remote code-execution channel if the host, account, DNS path, TLS delivery infrastructure, or installer publication process is compromised.

Attack Path

  1. The oo CLI is unavailable, causing an oo: command not found error.
  2. The Agent follows the documented first-time setup procedure.
  3. curl retrieves the current contents of https://cli.oomol.com/install.sh.
  4. The pipe passes the response directly to Bash without saving, reviewing, pinning, or verifying it.
  5. Bash executes all commands supplied by the remote endpoint with the privileges of the user running the Agent.
  6. A compromised installer could download additional payloads, access user-readable files, alter shell configuration, or execute any other operation permitted to that user.

Impact Assessment

Successful exploitation provides arbitrary command execution with the invoking user's privileges. The accessible scope may include the user's files, environment variables, local credentials available to that process, shell configuration, and network-accessible ...[truncated 187 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace curl | bash with a version-pinned installation artifact from a verifiable official release.
  • Download the artifact to a local file without executing it.
  • Publish and verify a cryptographic checksum and, preferably, a trusted digital signature before execution.
  • Display the exact version, source, expected checksum, and intended installation changes to the user.
  • Require explicit user approval before installing software.
  • Run installation with ordinary user privileges unless elevation is demonstrably required.
  • Prefer a trusted platform package manager or signed package that supports version pinning and integrity verification.
  • Fail closed when validation fails; do not fall back to executing unverified content.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:72
Finding

Unverified Remote PowerShell Script Executed Through Invoke-Expression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 72
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The Windows setup instruction retrieves a mutable PowerShell script with Invoke-RestMethod (irm) and sends its contents directly to Invoke-Expression (iex). This executes network-supplied code in memory without version pinning, manual review, checksum validation, or signature verification.

Although installing the CLI is related to enabling the declared Timelink functionality, executing an unverified remote script is not the least-privilege or minimum-risk installation method. The audited content does not establish malicious intent by the referenced host, but compromise of the delivery endpoint or publication process would let an attacker replace the installer after the Skill's review.

Attack Path

  1. The oo CLI is missing on a Windows host.
  2. The Agent or user follows the documented first-time setup instruction.
  3. Invoke-RestMethod downloads the current response from https://cli.oomol.com/install.ps1.
  4. The response is piped directly to Invoke-Expression.
  5. PowerShell interprets the response as commands without first verifying its origin, version, hash, or Authenticode signature.
  6. A compromised response executes arbitrary PowerShell operations with the current process's permissions.

Impact Assessment

Exploitation permits arbitrary code execution under the invoking Windows account. Potentially exposed resources include user-readable documents, environment variables, accessible credentials, PowerShell profiles, and network resources available to the account. If invoked from an elevated PowerShell session, the payload could make system-wide changes. The audited file does not itself contain a mechanism for bypas ...[truncated 50 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe remote content into Invoke-Expression.
  • Provide a versioned, signed installer from an official release channel.
  • Download the installer to disk and verify both its published cryptographic checksum and Authenticode signature.
  • Pin the expected release version rather than retrieving a mutable generic installer.
  • Require explicit user approval after showing the source, version, publisher, and intended changes.
  • Execute with standard-user permissions unless administrative access is strictly necessary and separately approved.
  • Abort installation if the signature, certificate chain, publisher, or checksum does not match the documented expected value.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends installing software by piping a remotely fetched script directly into bash, which prevents inspection or integrity verification before execution. Because this content sits inside an agent skill, an agent or user following the fallback instructions could execute arbitrary code from a remote source if the host, transport, or served script is compromised.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to use this skill for ANY Timelink request is an overly broad trigger that can cause the agent to invoke this skill in situations where a narrower, safer, or more context-appropriate path would be better. In an agent ecosystem, broad routing rules increase the chance of unintended tool use and can expand the operational blast radius if the skill later gains write capabilities or setup behaviors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.