Back to skill

Security audit

TinyURL

Security checks for vulnerabilities and agentic risk

Overview

The skill performs TinyURL actions as described, but its setup instructions include unverified internet installer commands that can execute code on the user's machine.

Review the setup path before installing. Use this skill only if you trust the OOMOL oo CLI distribution channel, and avoid running the pasted installer commands directly unless you can verify the script or use a safer package-manager or signed-release install method. Confirm any TinyURL creation payload before allowing it to run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installation Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup instructions download mutable scripts from cli.oomol.com and execute the responses immediately using Bash or PowerShell. The commands do not pin an installer version, verify a cryptographic checksum or signature, or give the user an opportunity to inspect the downloaded content before execution.

Although the installation domain appears associated with the CLI vendor, the effective code executed on a user's machine can change after this Skill has been reviewed. Compromise of the hosting infrastructure, publishing credentials, DNS resolution, TLS termination, or installer delivery pipeline could therefore turn the documented setup process into an arbitrary-code-execution channel.

Installing a CLI may legitimately require local changes, but direct execution of an unverified network response exceeds the minimum privilege and assurance needed to support TinyURL creation and listing. The Skill itself only needs access to the constrained oo commands declared in allowed-tools; unrestricted installer execution is a substantially broader capability.

Attack Path

  1. A user or agent attempts to use the Skill on a system where the oo CLI is unavailable.
  2. The command fails with oo: command not found, causing the user to follow the documented first-time setup instructions.
  3. An attacker compromises or gains control over the remote installer delivery path, such as the hosting service or publishing account.
  4. The curl or irm command retrieves the attacker-controlled response.
  5. Bash or PowerShell executes that response immediately without integrity or authenticity veri ...[truncated 958 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation commands.
  2. Keep CLI installation outside ordinary Skill execution and require an explicit, user-controlled setup action.
  3. Direct users to a version-pinned release artifact or trusted platform package manager.
  4. Download the installer to a local file rather than executing the network response directly.
  5. Publish a cryptographic SHA-256 digest and require verification before execution.
  6. Prefer signed artifacts and validate the signature against a documented, trusted publisher key.
  7. Allow users to inspect the downloaded script before running it.
  8. Document the exact files, permissions, network destinations, and system changes performed by the installer.
  9. Advise users not to execute the installer with elevated privileges unless a documented operation strictly requires them.
  10. Pin the CLI to a reviewed version and define a separate, explicit process for upgrades.

A safer installation pattern would follow this sequence:

bash
curl -fL -o install.sh "https://cli.oomol.com/releases/<pinned-version>/install.sh"
echo "<trusted-sha256>  install.sh" | sha256sum --check -
less install.sh
bash install.sh

The checksum must be obtained through a trusted, authenticated release channel rather than from the same mutable location as the installer.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a curl ... | bash installation command that downloads and immediately executes a remote script without verification. If the distribution endpoint, transport path, or upstream content is compromised, an agent or user following these instructions could execute arbitrary code on the host.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is excessively broad, directing the agent to use this skill for ANY TinyURL-related request and whenever a task involves TinyURL. That can cause over-selection of this skill for loosely related mentions, increasing the chance the agent performs connector-backed actions when a user only wanted discussion, analysis, or a non-operational response.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.