T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Remote Shell Script Downloaded and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 62
Vulnerability Type: Unverified remote payload execution through a shell
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command pipes a mutable network response directly into
bash. It does not pin a release version, verify a cryptographic checksum or publisher signature, or provide an opportunity to inspect the downloaded script before execution.HTTPS protects the connection in transit but does not guarantee that the server, publishing pipeline, or hosted script remains trustworthy. Because the effective payload is retrieved at execution time, it can change after the Skill has been reviewed. The installer also runs with all privileges available to the user launching the command.
This behavior is not necessary at the requested privilege level. Installing a CLI may be necessary for the Skill, but immediately executing an unverified remote response is not the minimum-privilege or minimum-risk installation method.
Attack Path
- The
ooCLI is absent and the action fails withoo: command not found. - The user or agent follows the documented first-time setup command.
- An attacker compromises the installer host, DNS resolution, TLS termination, or the vendor's script-publishing pipeline.
- The endpoint returns an attacker-controlled shell script.
curlstreams the response directly tobash, which executes it without integrity validation or review.- The payload performs arbitrary actions under the invoking user's account.
Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the user running the installation command. An attacker could read or modify user-accessible files, steal environment variables and local credentials, alter shell configuration, install pers ...[truncated 388 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashexecution pattern. - Prefer an official platform package manager or a version-pinned release artifact from a documented vendor repository.
- Download the installer or binary to a local file before execution.
- Pin an expected release version and verify a vendor-published cryptographic signature and a trusted SHA-256 or stronger digest.
- Fail closed if signature or checksum validation does not succeed.
- Allow the user to inspect the downloaded artifact and request explicit approval before executing it.
- Run installation without administrator privileges unless a specific installation step demonstrably requires elevation.
- Document the files, network endpoints, and system changes made by the installer.
- Remove the direct
