T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 57
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction streams a mutable script from an external server directly into Bash. The downloaded content is neither version-pinned nor verified using a cryptographic signature or trusted digest, and users cannot inspect it before execution.
HTTPS protects the connection in transit but does not ensure that the server, hosting account, release process, or delivered script remains trustworthy. Because the effective payload can change after the Skill has been reviewed, compromise of the distribution endpoint could turn this installation step into arbitrary remote code execution.
Installing the CLI may be necessary when
oois unavailable, but immediate pipe-to-shell execution exceeds the minimum privilege and trust required. A verified package or a download-review-verify-install workflow can provide the same functionality with substantially lower risk.Attack Path
- The
oocommand is unavailable, causing the user or agent to follow the documented fallback. - An attacker compromises the installer endpoint, its hosting infrastructure, DNS resolution, or the publisher’s deployment process.
- The attacker replaces or alters
install.shwith malicious shell commands. curlretrieves the attacker-controlled response and passes it directly to Bash.- Bash executes the payload without integrity verification or prior inspection.
- The payload performs arbitrary actions with the privileges of the account running the command.
Impact Assessment
Successful exploitation grants arbitrary command execution under the invoking user’s privileges. Depending on that account’s permissions, the payload could read or modify user fi ...[truncated 342 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation instruction. - Prefer an official operating-system package manager or a signed, version-pinned release artifact.
- If a standalone installer is required, download it to a local file rather than executing the network stream.
- Verify the file against a publisher signature and a SHA-256 digest obtained through a trusted, independently authenticated channel.
- Display or review the verified script before execution.
- Require explicit user approval before running an installer.
- Run installation with ordinary user privileges unless a narrowly defined operation demonstrably requires elevation.
- Pin the installer or CLI version so that the audited instructions resolve to a reproducible artifact.
- Remove the
