Back to skill

Security audit

Worksnaps

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Worksnaps read connector, but its fallback setup tells the agent to execute remote installer scripts without verification.

Install only if you are comfortable using OOMOL as an intermediary for Worksnaps data and avoid running the pasted installer commands directly; prefer a verified official installer, pinned release, or checksum/signature-verified installation before using the oo CLI.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64–68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The setup instructions download mutable scripts from an external server and immediately execute them through Bash or PowerShell. Neither command pins a specific installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded content before execution.

Although the source domain is associated with the declared OOMOL service and the instructions are only intended for first-time setup, the effective code executed is controlled by the remote endpoint and can change after the Skill has been reviewed. Installing the CLI is also outside the minimum privileges required to perform an individual Worksnaps read operation. An installation operation may modify executable paths, shell configuration, user files, or other local state.

The equivalent Windows pattern, irm ... | iex, has the same trust-boundary failure as curl ... | bash: server-provided text is interpreted directly as local code.

Attack Path

  1. The oo command is unavailable, causing the Agent or user to follow the first-time setup instructions.
  2. An attacker compromises the installer publication process, the remote server, or another relevant delivery-chain component.
  3. The attacker substitutes the expected installer with a malicious shell or PowerShell payload.
  4. curl or Invoke-RestMethod downloads the attacker-controlled response.
  5. The pipe passes the response directly to Bash or Invoke-Expression without integrity verification or inspection.
  6. The payload executes with the privileges of the user running the setup comma ...[truncated 841 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | bash and irm | iex installation patterns.

  • Prefer an operating-system package manager or a pinned release from a verified official repository.

  • Pin the CLI to an explicit version rather than retrieving a mutable installer.

  • Download the installer or binary to a local file without executing it immediately.

  • Verify a publisher signature or a checksum obtained through an independently authenticated channel before execution.

  • Present the exact artifact, version, source, expected changes, and required privileges to the user.

  • Require explicit user approval before installing software or modifying the local environment.

  • Run the installer without elevated privileges unless a documented installation step strictly requires them.

  • If an installation script must be supported, use a workflow equivalent to:

    bash
    curl -fSLo oo-install.sh "https://trusted.example/oo-install-v1.0.3.sh"
    echo "<PINNED_SHA256>  oo-install.sh" | sha256sum -c -
    less oo-install.sh
    bash oo-install.sh
    
  • Publish and verify signed release artifacts, document their expected filesystem changes, and provide uninstall instructions.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software by piping a remotely fetched script directly into a shell, which creates a classic supply-chain and remote code execution risk. If the install server, network path, or script content is compromised, arbitrary code would run immediately on the host with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill for "ANY Worksnaps request" and "Whenever a task involves Worksnaps," which is extremely broad and lacks boundaries or exclusion conditions. This can overlap with many ordinary references to Worksnaps and does not specify narrower trigger phrases or negative examples to constrain when the skill should activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.