Back to skill

Security audit

TomTom

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent TomTom lookup connector, but its setup instructions tell users to execute an unverified remote installer directly in a shell.

Review the install path before using this skill. Prefer installing the oo CLI from verified official documentation or a managed package source, and avoid running remote installer scripts directly unless you trust and have verified the source. Once installed, the listed TomTom actions are read-focused and the skill says credentials are handled server-side by OOMOL.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 59–63
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup instructions pipe remotely retrieved content directly into Bash or PowerShell. The installer is not pinned to an immutable release, and the instructions do not verify a cryptographic signature or checksum before execution. Consequently, the effective code executed by this Skill can change after the reviewed package has been published or audited.

HTTPS protects the connection in transit but does not guarantee that the current server-side payload is trustworthy or unchanged. Compromise of the distribution server, hosting account, release process, DNS infrastructure, or TLS credentials could turn the documented installation command into an arbitrary-code execution channel.

Installing a supporting CLI may be relevant to the declared TomTom connector functionality, but immediate execution of an unverified, mutable script is not the minimum privilege or safest installation method necessary to provide that functionality.

Attack Path

  1. The oo CLI is absent from the user's system.
  2. An Agent or user follows the first-time setup instructions in SKILL.md.
  3. The shell retrieves the current installer from cli.oomol.com.
  4. The pipeline executes the response immediately without saving it for inspection or verifying its integrity.
  5. If the remote source or delivery infrastructure has been compromised, attacker-controlled commands execute under the invoking user's account.
  6. Those commands can access data and perform operations available to that account, and may obtain broader system access if the installer prompts for or is run with elevated privilege ...[truncated 793 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash and irm | iex installation patterns.
  2. Direct users to an official, documented release page or trusted operating-system package manager.
  3. Pin installation instructions to a specific reviewed CLI version rather than a mutable installer endpoint.
  4. Require the installer or package to be downloaded to disk before execution so it can be inspected.
  5. Publish a SHA-256 or stronger digest through an independently protected channel and verify it before running the installer.
  6. Prefer cryptographic release signatures and document verification against a pinned, trusted signing key.
  7. Run installation with ordinary user privileges whenever possible, requesting narrowly scoped elevation only for operations that demonstrably require it.
  8. Keep the existing behavior of attempting connector actions before presenting setup instructions, but require explicit user approval before downloading or executing any installer.
  9. For managed environments, recommend centrally reviewed and administratively distributed CLI packages instead of runtime installation from the network.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes a one-line remote install command that pipes a fetched script directly into a shell. If an agent follows this guidance automatically, a compromised host, mirror, CDN, or transport path could result in arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest and description position the skill as only for 'searching and reading data,' but the body text explicitly anticipates write and destructive actions. This mismatch can mislead users or higher-level orchestration into granting broader trust or invoking the skill in contexts assumed to be read-only, increasing the chance of unintended state changes if connector capabilities expand or are exposed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text says to use this skill for ANY TomTom request and whenever a task involves TomTom, which is overly broad. That can cause unintended invocation on vague mentions of TomTom, routing user tasks through this skill without sufficient intent verification and potentially exposing data or causing unnecessary tool execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.