Back to skill

Security audit

updown.io

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing updown.io, but its first-time setup tells users to directly execute remote installer scripts, which deserves review before installation.

Install only if you are comfortable with OOMOL's oo CLI and updown.io account access. Prefer reviewing official install docs and verifying installer provenance before running remote shell or PowerShell installer commands; confirm any create, update, or delete action payload before execution.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The setup instructions retrieve mutable scripts from an external server and immediately pass their contents to a command interpreter. The Unix command pipes the response into Bash, while the Windows command uses Invoke-Expression to execute the downloaded PowerShell content.

Neither installation path pins a specific installer version nor verifies a cryptographic checksum or publisher signature. The executed payload is therefore determined by the remote server at installation time and can change after this Skill has been reviewed. Redirect handling and the lack of artifact inspection further prevent the user from confirming what will execute.

Installation is ancillary to the Skill's declared function of invoking the updown_io connector. Automatically executing an unverified installer exceeds the minimum behavior necessary to document or operate that connector.

Attack Path

  1. The oo command is unavailable, causing the user or Agent to follow the first-time setup instructions.
  2. An attacker compromises the installer host, its deployment pipeline, or another component capable of controlling the HTTPS-served installer.
  3. The attacker replaces the installer response with arbitrary shell or PowerShell commands.
  4. curl | bash or irm | iex executes the response immediately, without checksum, signature, version, or content verification.
  5. The payload runs with the permissions of the user who ...[truncated 1097 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove direct execution patterns such as curl | bash and irm | iex.
  2. Prefer an official platform package manager or a version-pinned release artifact from the project's verified release channel.
  3. Download the installer to a local file without executing it, using a URL that identifies an immutable version.
  4. Publish expected SHA-256 or stronger checksums through an independently protected channel and require verification before execution.
  5. Where supported, verify a cryptographic publisher signature using a pinned and documented signing identity.
  6. Instruct users to inspect the verified installer before running it as a separate command.
  7. Run installation without administrator or root privileges unless a specific, documented step strictly requires elevation.
  8. Document the files, permissions, network destinations, and system changes expected from the installer.
  9. For automated Agent use, treat missing CLI installation as a manual prerequisite rather than authorizing the Agent to fetch and execute remote code automatically.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI via a remote script piped directly into bash, which executes unreviewed code fetched at runtime. If the install endpoint, transport path, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states 'Use this skill for ANY updown.io request' and 'Whenever a task involves updown.io, use this skill,' which is a very broad activation condition. It does not narrow triggers or provide exclusion conditions, so it could match incidental mentions of updown.io rather than clear user intent to operate the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.