Back to skill

Security audit

Workable

Security checks for vulnerabilities and agentic risk

Overview

The Workable connector skill is mostly coherent, but its setup instructions include running an unverified remote installer directly in a shell.

Review the setup path before installing. Use this skill only if you are comfortable with OOMOL mediating Workable access and prefer installing the oo CLI through a safer official or verified method instead of pipe-to-shell commands. Confirm any future write or destructive Workable action explicitly.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:55
Finding

Unverified Remote Installer Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
  irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell
  ```

Technical Analysis

The installation instructions retrieve mutable scripts from external URLs and immediately execute the responses using Bash or PowerShell. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the operator an opportunity to inspect the downloaded code before execution.

TLS protects the network connection in transit, but it does not guarantee that the remote host will always return the same reviewed payload. Compromise of the hosting service, publishing credentials, DNS infrastructure, or release pipeline could cause arbitrary attacker-controlled code to be executed.

Installing the required CLI may support the declared Workable connector functionality, but direct execution of an unverified network response is not necessary. It grants the remote installer the full permissions of the user running the command and therefore exceeds the minimum capability needed to query Workable records.

Attack Path

  1. The oo CLI is unavailable, causing the user or Agent to follow the first-time setup instructions.
  2. The user or Agent runs the documented curl | bash or irm | iex command.
  3. The command retrieves a mutable script from cli.oomol.com.
  4. An attacker who has compromised the hosting or distribution path causes the server to return a malicious installer.
  5. Bash or PowerShell executes the response immediately without integrity verification or review. 6 ...[truncated 866 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both pipe-to-shell installation commands.
  2. Direct users to a documented, official installation guide or trusted platform package manager.
  3. Pin the CLI to a specific reviewed version rather than retrieving a mutable installer.
  4. Download the release artifact without executing it immediately.
  5. Publish and verify a SHA-256 checksum and, preferably, a cryptographic signature issued by a documented release key.
  6. Ensure verification fails closed before any installer or binary is executed.
  7. Run installation with ordinary user privileges unless elevated privileges are demonstrably required.
  8. If a script-based installer must remain available, instruct users to save and inspect it first, while still requiring signature or checksum validation before execution.

A safer conceptual workflow is:

bash
curl -fSLo oo-installer.sh "https://trusted.example/releases/<pinned-version>/install.sh"
echo "<published-sha256>  oo-installer.sh" | sha256sum --check -
less oo-installer.sh
bash oo-installer.sh

The artifact URL and expected digest must come from a trusted, authenticated release process and must be pinned to a specific version.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network without integrity checking, so a compromised host, CDN, DNS path, or upstream script could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for "ANY Workable request" and "Whenever a task involves Workable," which is an extremely broad activation condition. It does not define boundaries, exclusions, or negative examples, so ordinary requests that merely mention Workable could trigger the skill unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.