Back to skill

Security audit

urlscan.io

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its setup instructions ask users to run unverified remote installer scripts.

Review the setup path before installing. Prefer verified or version-pinned OOMOL installation instructions instead of blindly running the one-line installer, and confirm the exact submit_scan payload before allowing the skill to submit a URL.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57–61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from cli.oomol.com and pass their contents directly to Bash or PowerShell. Neither installation path pins a version, validates a cryptographic checksum, verifies a digital signature, nor gives the user an opportunity to inspect the downloaded script before execution.

Consequently, the code ultimately executed is not the code reviewed in this Skill. It can change whenever the remote resource changes. Compromise of the hosting infrastructure, CDN, DNS resolution, deployment process, or TLS trust chain could cause arbitrary attacker-controlled commands to run.

Installing a required CLI can be legitimate, and these instructions are only presented as a fallback when oo is unavailable. However, immediate remote-script execution exceeds the minimum privileges necessary to document or invoke the connector. The Skill could instead stop and direct the user to a verifiable, version-pinned installation procedure.

Attack Path

  1. The oo command is unavailable, causing the Agent or user to consult the first-time setup instructions.
  2. The Agent or user executes the documented Bash or PowerShell command.
  3. The command downloads the current installer from the external OOMOL endpoint.
  4. The downloaded response is passed directly to a local command interpreter without integrity verification.
  5. If the endpoint or delivery chain has been compromised, attacker-controlled commands execute with the privileges of the invoking process.

Impact Assessment

A malicious installer could obtain all perm ...[truncated 684 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all curl | bash and irm | iex installation instructions.
  2. Prefer a trusted platform package manager and pin the CLI to an explicitly reviewed version.
  3. If a standalone artifact is necessary, download it as a separate step from a versioned, immutable release URL.
  4. Publish and verify a cryptographic checksum and, preferably, a digital signature whose trust key is distributed through an independent channel.
  5. Abort installation if signature or checksum verification fails.
  6. Allow the user to inspect the downloaded artifact before execution and obtain explicit approval before running an installer.
  7. Execute installation with ordinary user privileges unless elevated privileges are demonstrably required.
  8. Document the expected files, network destinations, and system changes made by the installer.
  9. In automated Agent workflows, report that the CLI is missing and request user-directed installation rather than automatically executing remote setup code.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill includes a curl ... | bash installation command that downloads and executes a remote script directly from the network without integrity verification or package-signing validation. If the remote host, distribution path, DNS, TLS trust chain, or install script is compromised, arbitrary code would run on the user's system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition is overly broad because it instructs the agent to use this skill for ANY urlscan.io request instead of narrowly scoping when the skill is appropriate. Broad routing language can cause the agent to invoke this skill in situations where safer native handling, stricter review, or more context-specific logic would be preferable, increasing the chance of unintended actions or exposure to risky setup flows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.