T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:72- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 72–76
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from external URLs and immediately execute their contents using
bashor PowerShellInvoke-Expression. There is no version pinning, cryptographic signature verification, checksum validation, or opportunity to inspect the downloaded files before execution.HTTPS protects the connection in transit but does not guarantee that the remote script is safe or immutable. If the publisher infrastructure, hosting service, CDN, DNS resolution, TLS credentials, or release process is compromised, an attacker can replace the installer and obtain arbitrary code execution when an agent or user follows these instructions.
Installing the
ooCLI can be relevant to the Skill's declared Basin integration. However, directly executing an unverified network response is not the minimum privilege or minimum trust mechanism necessary to install that dependency. The installation process also falls outside the restrictedBash(oo *)runtime scope declared by the Skill and invokes general-purpose shells capable of arbitrary system modification.Attack Path
- The Skill attempts to perform a Basin operation, but the
ooCLI is not installed. - The agent or user follows the documented first-time setup procedure.
- An attacker compromises or gains control over the installer endpoint, its hosting infrastructure, DNS path, CDN, publisher account, or release pipeline.
- The attacker modifies the remote installer to include malicious shell or PowerShell commands.
curlorirmdownloads the attacker-controlled r ...[truncated 1243 chars]
- The Skill attempts to perform a Basin operation, but the
- Remediation
View remediation
Remediation Suggestions
- Remove both direct download-to-shell patterns, including
curl | bashandirm | iex. - Prefer an official operating-system package manager or a signed installer distributed through a trusted package repository.
- Pin the CLI to a specific reviewed version rather than retrieving a mutable latest installer.
- If direct download is unavoidable, download the artifact to a local file without executing it automatically.
- Publish and verify a cryptographic signature from a documented publisher key. At minimum, verify a version-specific SHA-256 checksum obtained through an independently protected channel.
- Display the source, version, destination, and requested permissions to the user and obtain explicit approval before installation.
- Run installation with ordinary user privileges wherever possible; do not request administrator or root access unless a specific operation requires it.
- Keep dependency installation separate from normal Skill execution. On a missing CLI, return a clear error and direct the user to reviewed installation documentation rather than automatically executing setup commands.
- After installation, verify the executable path, ownership, permissions, version, and publisher signature before invoking it.
- Recommend avoiding installation on systems that contain sensitive credentials until the installer and distribution chain have been independently reviewed.
- Remove both direct download-to-shell patterns, including
