T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The Browserless skill is coherent, but its setup instructions ask users to run unverified internet installer scripts directly, so it should be reviewed before installation.
Review this skill before installing. The normal Browserless actions are narrowly scoped, but do not run the listed installer commands unless you trust OOMOL's installer source and delivery path; prefer a signed or version-pinned package, checksum verification, or manually inspecting the downloaded installer first.
SKILL.md:57Unverified Remote Installer Download and Immediate Execution
The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk because any compromise of the hosting domain, transport chain, or installer script would immediately execute arbitrary code on the target system without review.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
No suspicious patterns detected.