T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:69- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a mutable shell script from an external URL and pipes it directly into Bash. The remote response is executed without version pinning, checksum validation, cryptographic signature verification, or an opportunity to inspect the downloaded file.
Although the endpoint uses HTTPS and its domain is consistent with the named vendor, those properties do not guarantee the integrity of future responses. The effective executable payload can change after the Skill has been reviewed. Compromise of the hosting account, installer infrastructure, domain resolution, or relevant TLS trust chain could therefore turn this command into an arbitrary-code execution channel.
Installing the required CLI may be necessary for the declared Chatwork connector functionality, but immediate execution of an unverified remote response exceeds the minimum safe installation procedure.
Attack Path
- A Chatwork operation fails because the
ooCLI is not installed. - The user or Agent follows the documented first-time setup instruction.
curlretrieves the current response fromhttps://cli.oomol.com/install.sh.- The response is passed directly to Bash without integrity verification or review.
- If the remote installer or delivery infrastructure has been compromised, attacker-controlled shell commands execute immediately.
- Those commands can perform any operation available to the account that invoked Bash.
Impact Assessment
A malicious installer response can obtain arbitrary code execution with the privileges of the invoking user. It could read or modify accessible files, access environment variables and locally a ...[truncated 282 chars]
- A Chatwork operation fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Pin installation instructions to a specific, reviewed CLI release rather than a mutable installer endpoint.
- Download the installer or release artifact to a local file before execution.
- Publish and verify a cryptographic signature or a checksum obtained through an independently authenticated channel.
- Prefer a trusted platform package manager with signed packages where available.
- Display the exact artifact version, source, and expected digest to the user.
- Require explicit user approval before executing any installer.
- Run installation with ordinary user privileges unless a documented component strictly requires elevation.
- Remove the direct
