T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Downloaded and Executed Through a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalThe first-time setup instructions execute remotely hosted installation scripts directly through local command interpreters:
bash curl -fsSL https://cli.oomol.com/install.sh | bashpowershell irm https://cli.oomol.com/install.ps1 | iexTechnical Analysis
Both installation commands retrieve mutable content from
cli.oomol.comand immediately execute it with the privileges of the invoking user. The instructions do not pin an immutable release, validate a cryptographic checksum, verify a digital signature, or allow the script to be inspected before execution.HTTPS protects the connection in transit but does not establish that the current script is safe or unchanged from the version reviewed during this audit. The effective code can change after the Skill has been published and audited. Compromise of the hosting service, publication pipeline, domain, DNS infrastructure, or TLS trust chain could consequently turn these installation commands into an arbitrary-code-execution channel.
Installing the
ooCLI supports the declared Bugsnag connector functionality, but immediate execution of unverified remote content exceeds the minimum mechanism required. A pinned, signed, and independently verified package would provide the same capability with substantially lower supply-chain risk.Attack Path
- The agent attempts to perform a Bugsnag operation using the
ooCLI. - The command fails because the CLI is not installed.
- The Skill directs the user or agent to run one of the remote installer commands.
- An attacker compromises or otherwise gains control over the mutable installation script or its delivery infrastructure.
curlor PowerShell downloads the attacker-controlled payload.bashorInvoke-Expressionexecutes the payload imm ...[truncated 1041 chars]
- The agent attempts to perform a Bugsnag operation using the
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation pipelines. - Pin installation instructions to a specific reviewed CLI release and immutable artifact.
- Download the installer or package to disk without executing it automatically.
- Publish trusted SHA-256 or stronger checksums and require users to verify them before execution.
- Digitally sign release artifacts and verify signatures against a documented, trusted public key.
- Prefer signed packages distributed through established platform package managers.
- Require explicit user approval before installing software or executing an installer.
- Document the files, permissions, network access, and system changes required by the installer.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- If a script remains necessary, display or review the downloaded script before invoking a shell and fail closed when verification cannot be completed.
- Remove the
