T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Remote Shell Script Downloaded and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command retrieves a mutable shell script from an external server and pipes it directly into
bash. The downloaded payload is neither pinned to a specific version nor verified using a cryptographic signature or trusted checksum. It is also not saved for inspection before execution.Although HTTPS protects the connection in transit under normal circumstances, it does not establish payload immutability or protect users if the distribution server, DNS infrastructure, certificate authority, or publisher account is compromised. Because the effective script can change after the Skill has been reviewed, its behavior cannot be determined from the package itself.
The instruction is only used as a fallback when the
oocommand is unavailable, but installing the CLI through an immediately executed remote script exceeds the minimum privilege required merely to document how Codacy queries are performed.Attack Path
- The Agent attempts to use the declared
ooCLI and receives anoo: command not founderror. - The Agent follows the first-time setup instruction in
SKILL.md. curlretrieves the current contents ofhttps://cli.oomol.com/install.sh.- The downloaded content is passed directly to
bashwithout validation or inspection. - If the hosting service or delivery chain has been compromised, attacker-controlled commands execute with the privileges of the user running the Agent.
- The payload could then read accessible data, alter user files, install additional software, access credentials available to the process, or establish persistence.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's account. The reachable s ...[truncated 378 chars]
- The Agent attempts to use the declared
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Link users to a documented, manual installation procedure rather than allowing an Agent to execute an installer automatically.
- Pin the CLI to a specific, reviewed release and download the corresponding immutable artifact.
- Publish and verify a cryptographic signature or a checksum obtained through a trusted, independent channel.
- Save the artifact locally and allow inspection before execution.
- Require explicit user approval before running any installer.
- Run installation with ordinary user privileges and avoid requesting administrative access unless a documented component strictly requires it.
- Prefer a trusted operating-system package manager with signed packages and version pinning where available.
- Document the expected files, permissions, and network endpoints used by the installer.
- Remove the direct
