Back to skill

Security audit

WhatsApp

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for WhatsApp, but it asks for broad CLI authority and includes unsafe direct remote installer commands.

Review before installing. Use this only if you trust OOMOL and are comfortable with an agent using your connected WhatsApp Business account. Prefer safer CLI installation instructions that verify a downloaded installer, and be careful to approve exact payloads before sending messages, uploading media, creating templates, or deleting templates.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:68
Finding

Unverified Remote Installation Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 68-76
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Vulnerable code:

markdown
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions retrieve mutable scripts from an external server and pass their contents directly to a command interpreter. Neither command pins a release, validates a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded payload before execution.

The URLs use HTTPS and are hosted on a domain consistent with the declared OOMOL provider, but transport encryption alone does not establish payload integrity over time. The effective code can change after this Skill has been reviewed. A compromise of the distribution server, its deployment pipeline, its TLS credentials, or another trusted component in the delivery chain could convert the documented installation flow into arbitrary local code execution.

Installation is presented as a conditional recovery step rather than an operation performed during every invocation. This reduces exposure frequency but does not eliminate the execution risk. Installing the CLI is relevant to the Skill's operation, but immediate pipe-to-shell execution is not the minimum privilege or safest mechanism necessary to perform that installation.

Attack Path

  1. The oo CLI is absent, causing an oo: command not found error.
  2. The agent or user follows the first-time setup instructions.
  3. The command downloads the current contents of install.sh or install.ps1.
  4. The downloaded content is passed directly to ...[truncated 1057 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash and irm | iex installation paths.
  2. Direct users to a version-pinned release artifact from an authenticated official release channel.
  3. Download the installer to a local file rather than piping it directly into an interpreter.
  4. Publish and verify a cryptographic signature or a checksum obtained through a separately authenticated channel.
  5. Display the resolved version, source, checksum, and intended changes before requesting explicit installation approval.
  6. Prefer a signed operating-system package or established package manager with integrity verification.
  7. Run installation with ordinary user privileges whenever possible and document any operation that genuinely requires elevation.
  8. Pin the CLI version known to be compatible with this Skill and define an explicit, separately approved upgrade procedure.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:5
Finding

Wildcard CLI Permission Exceeds the WhatsApp Connector Scope

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Overly broad tool authorization
Risk Level: Medium

Vulnerable code:

yaml
allowed-tools: [Bash(oo *)]

Technical Analysis

The Skill declares WhatsApp connector functionality and documents two required command forms:

bash
oo connector schema "whatsapp" --action "<action_name>"
oo connector run "whatsapp" --action "<action_name>" --data '<json>' --json

However, Bash(oo *) authorizes wildcard access to commands beginning with oo, rather than limiting execution to the WhatsApp schema and connector actions needed by the declared functionality. Depending on the enforcement semantics of the host, this can expose unrelated oo subcommands, connectors, authentication functions, or account operations.

The prose tells the agent not to invoke oo auth login proactively and requires confirmation for writes and destructive actions. These are useful behavioral safeguards, but they do not technically enforce least privilege. Prompt injection, malformed external content, or agent error could cause an authorized but unintended oo command to be run.

No evidence shows that the Skill currently exploits the broad permission. The security issue is the avoidable authorization gap between its declared WhatsApp purpose and the complete oo * command namespace.

Attack Path

  1. The Skill is loaded and receives permission to execute commands matching oo *.
  2. Untrusted task content, connector output, or another prompt source induces the agent to construct an unrelated oo command.
  3. The command passes the broad tool authorization because it starts with oo.
  4. The CLI performs an operation outside the intended WhatsApp connector scope using the user's authenticated OOMOL session.
  5. Depending on the available CLI commands and account privileges, the operation could access another connector, alt ...[truncated 721 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace Bash(oo *) with narrowly scoped permissions for the exact required command forms.
  2. Restrict the connector identifier to the literal value whatsapp.
  3. Enforce an allowlist containing only the WhatsApp actions documented by this Skill.
  4. Use a dedicated wrapper that validates the connector, action, argument structure, and JSON payload before invoking the CLI.
  5. Deny authentication, account-management, unrelated connector, and arbitrary CLI subcommands from the Skill execution context.
  6. Technically enforce separate approval gates for read, write, and destructive operations rather than relying solely on prose.
  7. Avoid constructing shell command strings from untrusted input; pass validated arguments through a structured process-execution interface where available.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes a remote script directly without verification. If the install endpoint, transport path, or hosting account is compromised, arbitrary code could run on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says to use this skill for "ANY WhatsApp request" and "Whenever a task involves WhatsApp," which is extremely broad and overlaps with many possible user intents. It does not provide constraints, exclusion conditions, or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.