T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 57
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction pipes a remotely downloaded, mutable shell script directly into
bash. The script is executed without prior inspection, version pinning, checksum validation, or cryptographic signature verification. Consequently, the code executed by this command can differ from the content assessed during the Skill audit.HTTPS authenticates the connection under normal conditions but does not guarantee that the hosted installer is safe or immutable. Compromise of the vendor's publishing account, web infrastructure, DNS, TLS termination, or installer build pipeline could turn this documented installation step into an arbitrary-code execution channel.
Installing the CLI can be relevant to the Skill's functionality, but immediate execution of an unverified remote script exceeds the minimum privileges and trust necessary to provide installation guidance.
Attack Path
- The
oocommand is unavailable, and execution fails withoo: command not found. - The user or Agent follows the first-time setup instruction in
SKILL.md. curlretrieves the current content ofhttps://cli.oomol.com/install.sh.- The response is passed directly to
bashwithout being saved, reviewed, pinned, or integrity-checked. - If the remote endpoint or its software supply chain has been compromised, attacker-controlled shell commands execute with the privileges of the user running the installation.
- The payload can access resources available to that user and may install additional components or persistence mechanisms.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's account. This may allow reading or modif ...[truncated 376 chars]
- The
- Remediation
View remediation
Remediation Suggestions
Remove the
curl | bashpipeline. Direct users to a versioned release artifact from an official release page and pin a specific CLI version. Download the artifact to disk, verify a vendor-published cryptographic signature or SHA-256 checksum through an independently protected channel, and only then execute or install it.Display the source, version, destination, and expected system changes before installation. Require explicit user approval for installation, avoid automatic fallback execution, and run the installer with ordinary user privileges unless a specific operation demonstrably requires elevation. Where available, prefer a trusted operating-system package manager with signed repository metadata.
