Back to skill

Security audit

Webvizio

Security checks for vulnerabilities and agentic risk

Overview

The skill is Webvizio-focused, but its setup instructions include unverified internet installer commands that can execute code on the user's machine.

Install only if you trust OOMOL and are comfortable with the oo CLI managing Webvizio connector actions. Do not run the documented installer pipe commands as-is; prefer a versioned, signed, checksum-verified installer or inspect the downloaded script before running it, and confirm any Webvizio write or delete action before execution.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Shell Script Execution on macOS and Linux

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 56
Vulnerability Type: Remote payload retrieval and immediate shell execution
Risk Level: High

Technical Analysis

The first-time setup instructions download a mutable remote script and pipe it directly into Bash:

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux

The effective executable content is not included in the reviewed project and therefore cannot be statically audited. The command does not pin a release version, verify a cryptographic signature or checksum, or provide an inspection step before execution.

HTTPS protects the connection in transit under normal conditions, but it does not ensure that the script remains identical to the version intended when the Skill was reviewed. Compromise of the remote server, domain, CDN, TLS termination infrastructure, or publishing process could cause arbitrary replacement content to execute. This behavior exceeds the minimum privileges needed merely to explain how to install the CLI because safer, verifiable installation methods are available.

Attack Path

  1. The oo command is unavailable, causing the user or agent to consult the first-time setup instructions.
  2. An attacker compromises or gains control of the remote installation endpoint or its release pipeline.
  3. The endpoint returns a modified install.sh payload.
  4. curl streams that payload directly to Bash without local inspection or integrity verification.
  5. The payload executes with all permissions held by the user running the command.
  6. The payload may access user-readable credentials and files, alter shell configuration, install additional software, or establish persistence.

Impact Assessment

Successful exploitation permits arbitrary command execution with the invoking user's privileges. The affected scope can include all files, credentials, environment variables, network resources, and applica ...[truncated 432 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the pipe-to-shell command with a pinned release artifact from an official, documented release repository.
  • Download the artifact to a local file rather than sending it directly to Bash.
  • Publish and verify a cryptographic signature or a checksum obtained through a separately authenticated channel.
  • Pin an explicit CLI version so the reviewed installation payload cannot change silently.
  • Allow the user to inspect the downloaded script before execution.
  • Require explicit user approval before running any installer.
  • Prefer a trusted platform package manager where the package source, version, and signature can be independently verified.
  • Document the files, directories, and permissions the installer requires, and run it without administrator privileges unless strictly necessary.

A safer workflow is: download a versioned artifact, verify its publisher signature and expected digest, inspect it, and only then execute it with the least-privileged account required.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:60
Finding

Unverified Remote PowerShell Script Execution on Windows

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 60
Vulnerability Type: Remote payload retrieval and immediate PowerShell execution
Risk Level: High

Technical Analysis

The Windows setup instructions retrieve a mutable remote PowerShell script and immediately evaluate it:

powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

irm retrieves content from the external endpoint, while iex interprets the response as PowerShell code. The downloaded script is not part of the audited project. No fixed release version, expected hash, publisher signature, local inspection, or content validation is required before execution.

Because the endpoint controls the code evaluated by PowerShell, the effective payload may change at any time after review. HTTPS alone does not mitigate compromise of the publisher, hosting service, domain, CDN, or release pipeline. Direct use of Invoke-Expression removes the opportunity to inspect and authenticate the payload before it runs.

Attack Path

  1. The oo CLI is missing on a Windows system.
  2. The user or agent follows the documented first-time installation command.
  3. An attacker compromises the installation endpoint or its publishing infrastructure.
  4. The endpoint supplies attacker-controlled PowerShell content.
  5. irm returns that content and pipes it directly to iex.
  6. PowerShell executes the payload with the invoking user's current permissions.
  7. The payload may read accessible credentials, modify user configuration, download additional components, or create persistence.

Impact Assessment

Exploitation enables arbitrary PowerShell execution in the security context of the invoking user. Potential access includes user files, environment variables, browser or application data available to that account, connected network services, and writable startup locations. Execution from an elevated PowerShell session could ...[truncated 393 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the irm ... | iex installation pattern.
  • Distribute a versioned installer or archive signed by a verifiable publisher certificate.
  • Download the installer to disk and verify its Authenticode signature and a published cryptographic digest before execution.
  • Pin the documented CLI version and avoid mutable unversioned installation endpoints.
  • Present the exact artifact and intended changes to the user, then obtain explicit approval before execution.
  • Run installation with standard-user privileges unless elevated access is demonstrably required.
  • Prefer a trusted Windows package repository that validates publisher identity and package integrity.
  • Document expected installation paths, binaries, configuration changes, and required permissions so anomalous behavior can be detected.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network immediately, enabling supply-chain compromise or man-in-the-middle/script replacement attacks to achieve arbitrary code execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Webvizio request" and "Whenever a task involves Webvizio," which is a very broad invocation condition in a manifest file. It does not define narrower trigger phrases, boundaries, or exclusion conditions, increasing the risk of unintended invocation for loosely related mentions of Webvizio.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.