T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Remote Shell Script Downloaded and Executed Without Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:59
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions retrieve a shell script from
https://cli.oomol.com/install.shand pipe the response directly into Bash. The script is neither included in the reviewed project nor pinned to an immutable version or digest. Consequently, its effective behavior cannot be determined from the audited artifact and can change after review.HTTPS protects the connection in transit but does not mitigate compromise of the hosting service, DNS or certificate infrastructure, the publisher account, or the remote deployment pipeline. It also does not prevent the publisher from replacing the script later. Directly piping the response into Bash removes the opportunity to inspect the downloaded artifact or verify its checksum or signature before execution.
Installing the CLI may be necessary when it is absent, but immediate execution of a mutable remote payload is not the minimum-privilege mechanism required for the Skill's declared read-only football-data functionality.
Attack Path
- The
ooCLI is unavailable, or the user is induced to treat it as unavailable. - The agent or user follows the first-time setup command in
SKILL.md. - An attacker compromises or controls the remote installer, its delivery infrastructure, or the publisher's deployment process.
curlretrieves the attacker-controlled response.- The pipe sends the response directly to Bash without local review, version pinning, checksum validation, or signature verification.
- Bash executes the payload with the privileges of the current user.
Impact Assessment
The remote payload obtains arbitrary command-execution capability under the current user's account. Depending on that account ...[truncated 469 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace the pipe-to-shell command with a version-pinned installer obtained from a trusted release page or package repository.
- Download the artifact to disk without executing it, then verify a publisher signature and a cryptographic digest distributed through an independent trusted channel.
- Display the exact version, source, expected digest, and requested privileges before installation.
- Require explicit user approval before executing installation commands.
- Run the installer without elevated privileges unless elevation is strictly required and separately justified.
- Prefer a reproducible package-manager installation with locked versions and package-signature verification.
- If a script remains necessary, vendor and audit the exact script or reference an immutable, digest-addressed release rather than a mutable URL.
