T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve scripts from external URLs and immediately execute their contents through Bash or PowerShell. The scripts are not pinned to an immutable release, downloaded for inspection, checked against an expected cryptographic digest, or verified using a trusted signature.
Although HTTPS provides transport protection, it does not guarantee that the remote script remains unchanged after this Skill has been reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, TLS termination environment, or installer deployment pipeline could cause arbitrary attacker-controlled commands to be returned and executed.
This behavior is not necessary at the documented level of privilege. Installing the required CLI may be necessary, but executing a mutable network response directly is not. It also falls outside the Skill's declared
allowed-tools: [Bash(oo *)]runtime restriction, which otherwise limits execution to theooCLI.The separately identified transmission of customer data through
oo connector runis disclosed by the Skill and is intrinsic to its stated Altoviz connector functionality. The reviewed file does not show hidden recipients, raw-token collection, or unrelated data exfiltration.Attack Path
- The
ooCLI is absent, or an Agent encounters an error interpreted asoo: command not found. - The Agent follows the first-time setup instructions in
SKILL.md. - The command requests the current installer from
cli.oomol.com. - An attacker who has compromised the download origin ...[truncated 1005 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation patterns.
- Pin the CLI to a specific, reviewed release rather than retrieving a mutable installer endpoint.
- Download the installation artifact to a local file without executing it automatically.
- Verify the artifact against a trusted, independently published SHA-256 digest or cryptographic signature before execution.
- Display the verified installer path and require explicit user approval before running it.
- Prefer an operating-system package manager or signed release package with version pinning and publisher verification.
- Keep installation outside normal Skill execution and preserve the declared
Bash(oo *)least-privilege boundary. - If automated installation is indispensable, restrict the source by exact version, enforce signature verification, fail closed on any verification error, and document the files and permissions modified by installation.
