Back to skill

Security audit

Zendesk

Security checks for vulnerabilities and agentic risk

Overview

This Zendesk skill is mostly coherent, but its setup instructions tell users to run an unverified remote installer directly in a shell.

Review the installer path before installing. Prefer installing the oo CLI through a verified, versioned source or inspect and verify the installer before execution. Also confirm exact Zendesk payloads before allowing ticket creation, replies, or updates because those actions can change customer-support records.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:62
Finding

Unverified Remote Installer Download and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The installation instructions download mutable scripts from cli.oomol.com and immediately execute their contents through Bash or PowerShell. They do not pin a release, validate a cryptographic checksum or signature, save the scripts for inspection, or otherwise establish that the executed content matches a reviewed artifact.

HTTPS protects the connection in transit but does not make the remote payload immutable. The effective code can change after the Skill itself has been reviewed. Compromise of the hosting service, publishing process, DNS or certificate infrastructure, or vendor account could therefore turn these installation commands into an arbitrary-code execution channel.

Installing the required CLI is legitimate setup functionality, but executing an unverified network response directly is not the minimum privilege or minimum-risk method needed to provide that functionality.

Attack Path

  1. The oo command is unavailable, causing the user or agent to consult the first-time setup instructions.
  2. The user or agent runs the documented Bash or PowerShell installation command.
  3. The command retrieves the current script from cli.oomol.com.
  4. The response body is passed directly to a command interpreter without integrity verification or prior inspection.
  5. A compromised or maliciously changed response executes arbitrary commands with the privileges of the invoking account.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's privileges. The payload could read or alter user-accessible files, collect credentials or en ...[truncated 454 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove direct curl | bash and irm | iex execution patterns.
  • Prefer a trusted package manager with a pinned, versioned CLI release.
  • If script-based installation is unavoidable:
    1. Download the installer to a local file without executing it.
    2. Pin an exact installer version or immutable artifact URL.
    3. Publish and verify a cryptographic checksum and preferably a vendor signature.
    4. Inspect or present the downloaded script before execution.
    5. Require explicit user approval before running the verified installer.
    6. Execute with ordinary user privileges unless elevation is demonstrably necessary.
  • Document the expected publisher identity, checksum/signature verification commands, and the filesystem or configuration changes made by installation.
  • Avoid automatic fallback installation by an agent; return a clear setup error and let the user perform the verified installation separately.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software via a remote script piped directly into a shell, which is a classic supply-chain and remote-code-execution risk. If the hosting domain, transport, or script contents are compromised, the agent could execute arbitrary attacker-controlled code on the local system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill for "ANY Zendesk request" and "Whenever a task involves Zendesk," which is extremely broad and lacks trigger boundaries or exclusion conditions. This can cause unintended invocation for casual references to Zendesk rather than clear action requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.