T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56-60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions pipe scripts downloaded from
cli.oomol.comdirectly into local command interpreters. The Unix command passes the HTTP response to Bash, while the Windows command invokes the downloaded PowerShell content throughInvoke-Expression.Neither instruction pins a specific installer version nor verifies a cryptographic signature or trusted checksum before execution. HTTPS protects the connection in transit, but it does not ensure that the server, publishing account, or hosted script remains uncompromised. The effective executable payload can also change after the Skill has been reviewed.
Installing the required CLI may be legitimate for the declared Brandfetch functionality, but executing an uninspected, mutable remote response is not the minimum privilege or minimum-risk approach necessary to perform that installation.
Attack Path
- A user attempts to use the Skill on a system where the
ooCLI is unavailable. - The documented first-time setup directs the user to execute one of the remote installation commands.
- An attacker compromises the installer host, publishing process, DNS or delivery infrastructure, or otherwise causes the URL to return modified script content.
- The shell executes the returned content immediately, without checksum validation, signature verification, version pinning, or a manual review step.
- The malicious installer performs arbitrary actions under the privileges of the user who ran the command and may retrieve additional payloads.
Impact Assessment
Successful exploit ...[truncated 581 chars]
- A user attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation instructions. - Link to a version-pinned release artifact from an authenticated release channel.
- Require users to download the installer to disk before execution.
- Publish an expected SHA-256 or stronger digest over a separately authenticated channel and require verification before execution.
- Prefer a cryptographically signed package and document signature verification using a pinned, trusted signing identity.
- Allow users to inspect the downloaded script before running it.
- Document the installer's expected network access, filesystem modifications, and required privileges.
- Avoid requesting administrative privileges unless a specific installation operation requires them.
- Prefer established platform package managers with signed repositories and pinned package versions where available.
- Remove direct
