Back to skill

Security audit

2Chat

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent 2Chat connector, but its setup instructions tell users to execute unverified remote installer scripts directly in a shell.

Review the setup commands before installing. Prefer installing the oo CLI from a versioned, signed, or checksum-verified source rather than running the documented pipe-to-shell commands. Once oo is already installed and connected, the skill's normal 2Chat actions are disclosed and should require confirmation before changing 2Chat data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:59
Finding

Remote Installation Script Executed Directly Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

Technical Analysis

The installation command retrieves a mutable script from an external URL and passes it directly to Bash. The payload is executed without a pinned version, cryptographic checksum, publisher-signature verification, or opportunity for local review.

Although installation of the oo CLI supports the Skill's stated functionality and the domain is consistent with the declared OOMOL integration, executing a remotely hosted script is not the minimum-privilege installation method. The repository does not establish what commands the remote script performs, and its contents can change after the Skill has been reviewed. The downloaded payload receives the full permissions of the user running the command, which extends beyond the Skill's declared runtime allowance of Bash(oo *).

Attack Path

  1. A user or Agent attempts to use the Skill on a system where the oo CLI is unavailable.
  2. The command fails with oo: command not found.
  3. The fallback instructions cause the installation command to be executed.
  4. The current content of https://cli.oomol.com/install.sh is downloaded.
  5. Bash executes the content immediately without integrity or authenticity verification.
  6. If the hosting account, domain, DNS/TLS path, or installation script has been compromised, attacker-controlled commands execute with the invoking user's privileges.

Impact Assessment

A malicious remote payload could execute arbitrary commands with the privileges of the invoking user. Depending on those privileges and the host configuration, it could read or modify accessible files, steal credentials, alter shell configuration, install additional software, or establish persistence. Running the command thr ...[truncated 275 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe downloaded content directly into a shell.
  • Distribute the CLI through a trusted, versioned package manager or a pinned release artifact.
  • Download the installer as a file without executing it, then verify a publisher signature and a pinned SHA-256 digest.
  • Pin an explicit installer or CLI version so the reviewed artifact cannot change silently.
  • Permit inspection of the downloaded script before execution.
  • Document the files, permissions, and configuration changes made by the installer.
  • Run installation with ordinary user privileges unless a narrowly defined operation explicitly requires elevation.
  • Keep installation outside automated Skill execution and require informed user approval before running any installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:63
Finding

Remote Installation Script Executed Directly Through PowerShell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

irm retrieves PowerShell source code from an external URL and sends the response directly to iex (Invoke-Expression). This causes the mutable remote response to execute immediately in the current PowerShell process. The command does not pin a release, verify a cryptographic digest or publisher signature, or preserve the script for review before execution.

Installing the required CLI is related to the declared connector functionality, but immediate execution of an unverified network response exceeds the minimum privileges necessary to provide installation guidance. The repository contains no copy of the executed payload and therefore cannot constrain or establish its behavior at audit time.

Attack Path

  1. A user or Agent attempts to invoke the Skill on Windows without the oo CLI installed.
  2. The resulting command-not-found condition leads to the documented fallback procedure.
  3. PowerShell retrieves the current response from https://cli.oomol.com/install.ps1.
  4. The response is passed directly to Invoke-Expression.
  5. PowerShell executes it with the current process and user privileges.
  6. Compromise of the hosting infrastructure, domain, network trust path, or installer content allows an attacker to substitute arbitrary PowerShell commands.

Impact Assessment

A substituted payload could perform any operation available to the current PowerShell user, including reading accessible documents and credentials, modifying user configuration, downloading additional executables, or creating persistence. If PowerShell is running with administrative privileges, the payload could potentially modify system-wide settings and compromise the entire Windo ...[truncated 183 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the Invoke-RestMethod | Invoke-Expression installation pattern.
  • Use a signed, versioned Windows package or pinned release artifact from a verified distribution channel.
  • Download the installer separately and validate both its Authenticode signature and a pinned cryptographic digest before execution.
  • Pin the expected CLI version and document the trusted publisher identity.
  • Show the user the artifact source, expected integrity value, and intended changes before requesting approval.
  • Execute the installer under a standard user account wherever possible.
  • Do not automatically elevate privileges or bypass PowerShell execution-policy and security controls.
  • Keep installation as an explicit user-approved setup action rather than an automatically executed Skill operation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software via a remote script piped directly into a shell (curl ... | bash), which executes unreviewed code fetched at runtime. If the install endpoint, transport, hosting, or supply chain is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says to use this skill for "ANY 2Chat request" and "Whenever a task involves 2Chat," which is an expansive activation condition without clear scope boundaries or exclusions. In a manifest file, this can cause unintended invocation for loosely related mentions of 2Chat rather than clearly defined actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.