Back to skill

Security audit

Vestaboard

Security checks for vulnerabilities and agentic risk

Overview

The Vestaboard connector behavior is coherent, but its fallback setup tells users to run unverified remote installer scripts directly in a shell.

Review the oo CLI installation path before installing. Prefer official, version-pinned, checksum- or signature-verified installation instructions instead of running the pasted curl|bash or irm|iex commands directly. The Vestaboard connector actions themselves appear scoped and disclosed once oo is already installed and connected.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58-62
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions retrieve mutable scripts from cli.oomol.com and pass their contents directly to Bash or PowerShell. The downloaded code is therefore executed before the user can inspect it. The instructions do not pin a release, verify a cryptographic checksum or signature, or otherwise establish that the retrieved content matches an audited version.

HTTPS protects the connection in transit but does not protect against compromise of the hosting account, web server, publishing pipeline, or signing authority. Because the installer source is not included in the project, its behavior and effective privileges cannot be assessed from this package. Its payload may also change after the Skill has been reviewed.

These commands are presented only as fallback installation steps when oo is unavailable, rather than being run during every action. That reduces exposure frequency but does not remove the arbitrary-code execution risk when setup is required.

Attack Path

  1. A user attempts to use the Skill without the oo CLI installed.
  2. The documented fallback directs the user to run one of the remote installation commands.
  3. An attacker compromises the remote installer, its hosting or release pipeline, or another component capable of controlling the returned response.
  4. The attacker substitutes malicious shell or PowerShell content for the legitimate installer.
  5. bash or iex immediately interprets the response without integrity validation or review.
  6. The malicious payload executes with all permissions available to the invoking user.

Impa

...[truncated 869 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex execution patterns.
  2. Refer users to a documented package-manager installation method or a version-pinned release artifact from an authenticated release channel.
  3. Require the installer to be downloaded to a local file before execution so it can be inspected:
    bash
    curl -fSLo oo-install.sh "https://example.invalid/releases/vX.Y.Z/install.sh"
    
  4. Publish a cryptographic digest through an independently protected channel and verify it before execution:
    bash
    echo "<expected-sha256>  oo-install.sh" | sha256sum --check -
    
  5. Prefer signed release artifacts and verify the publisher's signature using a pinned, documented public key.
  6. Pin an explicit CLI version instead of retrieving a mutable generic installer.
  7. Execute installation with ordinary user privileges unless a narrowly defined operation genuinely requires elevation. Clearly disclose every filesystem location and configuration item the installer changes.
  8. For PowerShell, apply the same download, signature or hash verification, inspection, and separate execution process rather than passing the network response directly to Invoke-Expression.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to execute a remote install script via curl ... | bash, which runs code fetched over the network directly in the shell without prior verification. If the hosting endpoint, transport, or upstream script is compromised, this can lead to arbitrary code execution on the user's machine, making the skill materially more dangerous because the behavior is embedded in a trusted setup flow.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest frames this as a skill for handling Vestaboard requests by using the existing connector, but the documentation also instructs the agent to install the oo CLI, run oo auth login, and direct the user to a connection URL. Those setup capabilities are ancillary environment/bootstrap actions rather than Vestaboard read/create/update operations themselves.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.