Back to skill

Security audit

GoodVerify

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible GoodVerify CLI helper, but its install path runs an unpinned remote shell script and it handles sensitive contact data and API keys with limited safeguards.

Review this skill before installing. Do not run the documented pipe-to-shell installer unless you independently trust and inspect the installer or have a pinned, verified release. Treat GoodVerify API keys, emails, phone numbers, addresses, and owner lookup results as sensitive, and confirm user consent before sending them to the GoodVerify service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Unverified Remote Installation Script Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 30
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://raw.githubusercontent.com/agoodway/goodverify_cli/main/install.sh | sh

Technical Analysis

The installation instructions download a shell script from the mutable main branch of a personal GitHub repository and immediately pipe it to sh. The command does not pin an immutable release or commit, verify a cryptographic signature or checksum, save the script for inspection, or isolate its execution.

The payload that executes can therefore change after this Skill has been reviewed. The repository owner—or an attacker who compromises the GitHub account, repository, branch, or release process—could replace install.sh with arbitrary shell commands. Those commands would inherit the permissions, environment variables, filesystem access, and network access of the user running the installation.

Installing the required CLI is relevant to the Skill's stated functionality. However, direct pipe-to-shell execution exceeds the minimum safe mechanism necessary to perform that installation because less risky, verifiable installation methods are available. The remote script was not included in the audited project, so its current contents and privilege behavior could not be assessed.

Attack Path

  1. An agent follows SKILL.md and determines that the goodverify CLI is not installed.
  2. An attacker modifies main/install.sh after compromising the repository or its maintainer account, or the repository owner publishes a malicious update.
  3. The agent runs the documented curl | sh command.
  4. curl retrieves the current remote payload without pinning or integrity verification.
  5. The shell executes the payload immediately, without a review or confirmation boundary.
  6. The payload performs arbitrary actions using the invoking user's privileges.

Impact Assessment

...[truncated 765 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation instruction.
  2. Publish versioned, reproducible CLI releases through a trusted package manager or release channel.
  3. Pin installation artifacts to an immutable version, release, or commit rather than the mutable main branch.
  4. Publish a SHA-256 checksum and preferably a cryptographic signature through an independently authenticated channel.
  5. Download the installer or binary to a local file, verify its integrity and authenticity, and allow inspection before execution.
  6. Require explicit user approval before installing or executing third-party software.
  7. Run installation with the least privileged account possible and do not request elevated privileges unless a documented operation strictly requires them.
  8. Document the files, directories, network endpoints, and configuration changes made by the installer.
  9. Prefer a transparent sequence such as:
bash
curl -fL -o goodverify-install.sh "https://example.invalid/releases/v0.1.0/install.sh"
echo "<expected-sha256>  goodverify-install.sh" | sha256sum --check -
less goodverify-install.sh
sh goodverify-install.sh

The placeholder URL and checksum must be replaced with a trusted immutable release artifact and its verified digest.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (7)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific use of curl ... | sh is a command-chaining pattern that executes unreviewed remote content immediately. In an agent skill context, this is especially dangerous because it normalizes a one-step arbitrary execution flow that could be triggered without adequate scrutiny.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

If not installed:

bash
curl -fsSL https://raw.githubusercontent.com/agoodway/goodverify_cli/main/install.sh | sh

If not configured, ask the user for their API key and base URL, then:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The invocation guidance includes broad triggers like 'verify email', 'verify phone', and 'verify address', which can match ordinary conversational requests and cause the skill to activate more often than intended. In this context, over-broad activation is risky because the skill sends potentially sensitive personal data to an external API and can perform enrichment beyond simple validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages sending emails, phone numbers, addresses, and potentially property-linked identity data to an external API without warning that this information leaves the local environment. Users may unknowingly transmit sensitive personal data to a third party, creating privacy, compliance, and consent risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions tell the agent to ask the user for an API key and then place it directly into a command, but they do not warn that the credential is sensitive. This can lead to users pasting secrets into chat, command history, logs, or transcripts where they may be exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as contact-data verification, but the address workflow also exposes owner enrichment data such as names, other addresses, phones, and emails. This expands the skill from validation into person/property intelligence gathering, which can enable privacy-invasive lookups, profiling, or misuse beyond the user’s likely expectation.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends installing the CLI by piping a remotely fetched script directly into the shell. This creates a supply-chain and remote code execution risk because any compromise of the source, transport, or referenced script immediately results in arbitrary command execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

If not installed:

bash
curl -fsSL https://raw.githubusercontent.com/agoodway/goodverify_cli/main/install.sh | sh

If not configured, ask the user for their API key and base URL, then:

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames the skill as a verifier for emails, phones, addresses, and related usage checks. The documentation also instructs the agent to ask the user for an API key and run a configuration command that stores credentials, which is a credential-management capability rather than direct verification behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.