T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63-67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions download mutable content from
cli.oomol.comand immediately pass it to a command interpreter. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded file before execution.HTTPS provides transport protection but does not establish that the script itself is safe. Compromise of the hosting infrastructure, domain, CDN, publishing credentials, or installer-generation process could replace the script after the Skill has been reviewed. The effective code executed by these instructions can therefore change independently of this package.
Although installation is presented as a fallback for a missing CLI and the domain is associated with the declared service provider, direct remote-script execution is not required to perform the Skill's normal APIVerve operations. It exceeds the minimum privilege needed by an already-installed client and creates a supply-chain code-execution channel.
Attack Path
- A user or Agent attempts an APIVerve action and receives an
oo: command not founderror. - The fallback instructions cause the macOS/Linux command or Windows PowerShell command to be executed.
- The current response from
cli.oomol.comis downloaded without version pinning or integrity verification. bashor PowerShell immediately interprets the response as executable code.- If the remote script or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the invoking process.
- Those commands ...[truncated 969 chars]
- A user or Agent attempts an APIVerve action and receives an
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands from the Skill instructions.
- Direct users to a documented package manager or a versioned release page instead of executing a mutable URL.
- Pin the CLI to an explicitly reviewed version.
- Publish SHA-256 checksums and cryptographic signatures through an independently protected channel.
- Require users to download the installer to a local file, verify its signature or checksum, and inspect it before execution.
- Keep CLI installation as an explicit, user-controlled prerequisite rather than allowing an Agent to perform it automatically after a command failure.
- Run installation with ordinary user privileges whenever possible and document any permissions genuinely required.
- If automated installation is unavoidable, use a signed package repository with version pinning and fail closed when integrity verification cannot be completed.
