T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command streams a remotely hosted shell script directly into Bash. The Skill does not pin the installer to a reviewed version or require signature, checksum, or content verification before execution. Consequently, the code executed at installation time can differ from the content available when the Skill was audited.
Installing the
ooCLI is relevant when that required tool is absent, but immediate remote-to-shell execution is not the minimum privilege or safest mechanism necessary to install it. Separating download, verification, inspection, and execution would materially reduce supply-chain risk.Attack Path
- An attacker compromises
cli.oomol.com, its deployment pipeline, hosting account, DNS resolution, or another relevant delivery-chain component. - The attacker replaces
install.shwith a malicious payload. - A user or agent encounters the documented
oo: command not foundcondition and follows the fallback installation command. curldownloads the current attacker-controlled response and passes it directly to Bash.- Bash executes the payload without package-version pinning or integrity verification.
Impact Assessment
The downloaded script obtains arbitrary code execution with the privileges of the user running the command. Depending on those privileges and the malicious payload, this could permit access to user-readable files and credentials, modification or destruction of data, installation of persistence, or further network activity. If invoked by a privileged user, the impact could extend to system-wide compromise.
- An attacker compromises
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Prefer a trusted operating-system package manager or a version-pinned release from the CLI's official repository.
- If a standalone installer is necessary, download it to a non-executable file first.
- Publish and require verification of a cryptographic signature or version-specific checksum obtained through an independently protected channel.
- Allow the user to inspect the downloaded script before execution.
- Execute the installer without elevated privileges unless a documented installation step strictly requires them.
- Pin the installer or CLI version so the reviewed artifact cannot change silently.
- Remove the direct
