T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:79- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 79–83
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions pipe network responses directly into Bash or PowerShell. Neither command pins an installer version, verifies a cryptographic checksum or signature, nor gives the user an opportunity to inspect the downloaded code before execution.
Although
cli.oomol.comis consistent with the Skill's declared OOMOL integration, the effective payload is mutable and exists outside the audited project. Consequently, its behavior can change after the Skill has been reviewed. Compromise of the hosting service, deployment pipeline, DNS resolution, TLS endpoint, or OOMOL distribution infrastructure could cause arbitrary attacker-controlled commands to be executed.Installing the
ooCLI is relevant only when the required CLI is missing, but immediate execution of an unverified remote response exceeds the minimum safe mechanism necessary to perform that installation.Attack Path
- The Agent attempts to use the Skill and receives an
oo: command not founderror. - The Agent follows the first-time setup instructions in
SKILL.md. - The applicable command downloads the current contents of
install.shorinstall.ps1. - Bash or PowerShell executes the response immediately without integrity or authenticity verification beyond transport-level TLS.
- If the remote delivery path has been compromised, attacker-controlled installer code executes with the permissions of the user running the Agent.
- The payload can inspect accessible local data, modify the environment, install additional software, or misuse existing authenticated sessions and credentials.
...[truncated 667 chars]
- The Agent attempts to use the Skill and receives an
- Remediation
View remediation
Remediation Suggestions
-
Replace direct pipe-to-shell execution with a staged installation process:
- Download the installer to a local file.
- Pin an explicit CLI release version.
- Verify a vendor-published SHA-256 or stronger checksum.
- Prefer verification using a trusted code-signing key.
- Inspect the verified artifact before executing it.
-
Prefer a trusted, version-pinned package manager or signed release artifact over a mutable installation endpoint.
-
Require explicit user approval before downloading or executing installation code. The Agent should not install software automatically merely because a command is unavailable.
-
Document the expected installer source, release version, checksum, signer identity, required permissions, and files or directories modified during installation.
-
Run the installer with standard user privileges and avoid
sudo, administrator PowerShell, or other privilege elevation unless independently justified and explicitly approved. -
For PowerShell, download the script as a file and validate its Authenticode signature or published digest before invoking it. For macOS and Linux, perform equivalent signature or checksum validation before running Bash.
-
