T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:70- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70–74
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from
cli.oomol.comand pass them directly to a command interpreter. The Unix command pipes the HTTP response into Bash, while the Windows command passes the response to PowerShell'sInvoke-Expression.Neither installation path pins a release version, verifies a cryptographic signature or checksum, nor provides an opportunity to inspect the downloaded script before execution. HTTPS protects data in transit but does not protect against a compromised distribution server, publishing account, DNS or certificate infrastructure, or an unexpectedly modified upstream installer.
The effective executable payload can therefore change after the Skill package has been audited. Although installation is presented as a fallback for when
oois unavailable, remote script execution is not required during ordinary connector operations and exceeds the minimum privileges needed for the Skill's normal Close CRM functionality.Attack Path
- The user or agent attempts to invoke the Skill on a system where the
ooCLI is not installed. - The documented first-time setup procedure is selected.
- An attacker compromises the installer host, its deployment pipeline, or another part of the trusted delivery chain and replaces the installer with malicious content.
curlorInvoke-RestMethoddownloads the current remote response.- Bash or PowerShell executes the response immediately without integrity verification or review.
- The payload performs arbitrary actions with the privileges of the user running the installation c ...[truncated 803 chars]
- The user or agent attempts to invoke the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation commands from the Skill instructions. - Direct users to a version-pinned release artifact or a trusted operating-system package manager instead of a mutable installer endpoint.
- Require the artifact to be downloaded to disk before execution so that it can be inspected.
- Publish a SHA-256 or stronger checksum through an independently protected release channel and verify it before running the installer.
- Prefer cryptographically signed packages and verify the publisher signature and signing-chain validity.
- Keep installation outside autonomous Skill execution. The Skill should stop and ask the user to complete the verified installation procedure manually.
- Run installation without administrator privileges unless a documented component strictly requires elevation.
- Apply equivalent version pinning, signature validation, and manual review requirements to both the Bash and PowerShell installation paths.
- Document the files, permissions, network endpoints, and persistence mechanisms used by the installer so users can evaluate the requested privileges.
- Remove direct
