T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:69- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command pipes a mutable network response directly into
bash. The downloaded script is neither version-pinned nor verified using a cryptographic signature or checksum, and the command provides no opportunity to inspect the payload before execution.HTTPS protects the connection in transit but does not establish that the current script matches the version reviewed with this Skill. If the hosting service, publishing account, DNS resolution, certificate trust chain, or deployment pipeline is compromised, the URL can return attacker-controlled shell commands.
The installer is only needed when the
ooCLI is unavailable, but unrestricted remote shell execution exceeds the minimum privilege needed to document or install a known CLI artifact. The Skill should instead use a fixed, independently verifiable release.Attack Path
- An attacker compromises the installer host, its deployment pipeline, publishing account, or another component capable of changing the response from
https://cli.oomol.com/install.sh. - The attacker replaces the installer response with malicious shell commands.
- The
ooCLI is absent, causing the documented first-time setup path to be used. - A user or agent runs the documented
curl | bashcommand. bashexecutes the attacker-controlled response immediately with the privileges of the invoking account.- The payload can access resources available to that account and may attempt further compromise or persistence.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's privileges. The payload could read or modify user-accessible files, access credentials available to ...[truncated 211 chars]
- An attacker compromises the installer host, its deployment pipeline, publishing account, or another component capable of changing the response from
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation instruction. - Refer users to a version-pinned release hosted in the project's verified official repository.
- Download the installer or binary to a local file without executing it automatically.
- Publish and require verification of a cryptographic signature or checksum obtained through an independently protected channel.
- Allow inspection of the downloaded script before execution.
- Prefer a signed operating-system package or trusted package-manager distribution.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Document the exact files, permissions, and system changes performed by the installer.
- Remove the direct
