T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions pipe remotely downloaded content directly into Bash or PowerShell. The downloaded installer is mutable and is executed without version pinning, cryptographic signature verification, checksum validation, or an opportunity for local review.
Although the download domain is associated with the declared OOMOL CLI, this pattern makes the effective code executed by the Skill dependent on whatever the remote endpoint serves at invocation time. Consequently, the installer can change after the Skill has been audited. Compromise of the hosting infrastructure, publishing account, DNS resolution, TLS termination, or installer distribution process could cause arbitrary attacker-controlled commands to execute.
Installing the required CLI is relevant to the Skill's functionality, but immediate execution of an unverified remote response exceeds the minimum necessary installation behavior. A safer workflow can download a fixed release, authenticate it, and execute it only after verification.
Attack Path
- The
oocommand is unavailable and an agent or user follows the first-time setup instructions. - An attacker compromises or otherwise gains control over the installer delivery path or remote installer content.
- The attacker modifies
install.shorinstall.ps1to include malicious commands. curl | bashorirm | iexpasses the response directly to a command interpreter.- The malicious commands execute without integrity validation or prior inspection.
- The payload accesses resources available to the invoking ...[truncated 871 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashandirm | iexinstallation commands. - Pin installation instructions to a specific, immutable CLI version rather than a mutable installer URL.
- Download the release artifact to a local file without executing it immediately.
- Publish the expected SHA-256 digest through an independently protected release channel and verify it before execution.
- Prefer signed release artifacts and verify the publisher signature against a documented, pinned public key.
- Use a trusted platform package manager where packages are versioned and authenticated.
- Allow the user to inspect and explicitly approve the downloaded artifact before execution.
- Run installation with ordinary user privileges and avoid requesting administrative access unless a specific installation step requires it.
- Document the files, directories, network endpoints, and configuration changes made by the installer.
- Fail closed if integrity or signature verification cannot be completed.
A safer installation sequence should follow this model:
bash curl -fL -o oo-installer.sh "https://trusted.example/releases/vX.Y.Z/install.sh" echo "EXPECTED_SHA256 oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.shThe release URL and digest must be replaced with authentic, version-specific values published through a protected release process.
- Remove the direct
