T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions download mutable content from an external server and immediately pass it to a command interpreter. The Unix command pipes the HTTP response directly into Bash, while the Windows command evaluates the downloaded PowerShell content through
iex.No version pinning, cryptographic checksum validation, digital-signature verification, or opportunity for local inspection is provided. Although HTTPS protects the connection in transit, it does not ensure that the delivered script remains identical to the version reviewed. A compromise of the remote server, hosting account, deployment pipeline, or associated infrastructure could therefore change the effective payload at any time.
Installing the CLI may be relevant to the skill's declared Cloudinary functionality, but immediate execution of an unverified remote response exceeds the minimum privileges and safeguards necessary to perform that installation.
Attack Path
- The
oocommand is unavailable, causing the agent or user to consult the first-time setup instructions. - An attacker compromises the installer endpoint, its deployment pipeline, or another component capable of controlling the returned script.
- The victim runs the documented
curl | bashorirm | iexcommand. - The attacker-controlled response is supplied directly to the local shell without integrity verification.
- Arbitrary commands execute with th ...[truncated 855 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove instructions that pipe downloaded content directly into Bash or evaluate it with PowerShell.
- Direct users to a version-pinned release artifact from the official distribution channel.
- Download the installer or binary to a local file without executing it automatically.
- Publish and require verification of a cryptographic checksum from a separately authenticated source.
- Prefer signed release artifacts and validate the publisher's digital signature before execution.
- Allow the user to inspect the downloaded installer and require explicit approval before running it.
- Run installation with ordinary user privileges unless a specific installation step demonstrably requires elevation.
- Document the files, commands, network destinations, and configuration changes performed by the installer.
- Where supported, recommend a trusted package manager with a pinned package version and signature-verification controls.
