T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent Aviationstack connector, but its setup instructions tell users to execute remote installer scripts directly in a shell.
Review the installer path before installing. Prefer installing the oo CLI through a verified package or separately downloaded installer with published checksums/signatures, and avoid running the one-line remote shell commands unless you trust OOMOL's installer delivery path and understand it can execute code on your machine.
SKILL.md:63Unverified Remote Installation Scripts Executed Directly by Shells
The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). If the remote host, CDN, DNS, TLS trust chain, or distribution pipeline is compromised, arbitrary code will execute immediately on the user's machine with the user's privileges.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Aviationstack request" and "Whenever a task involves Aviationstack," without defining boundaries or exclusions. That activation scope is broad and lacks negative examples, making it unclear when the skill should or should not be selected.
No suspicious patterns detected.