T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:55- Finding
Unverified Remote Bash Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The setup instruction downloads a mutable script from
cli.oomol.comand passes it directly to Bash without first saving, inspecting, or cryptographically verifying it. HTTPS protects the connection in transit but does not pin the installer content or guarantee that future content at the URL will match what was reviewed.If the domain, hosting infrastructure, CDN, DNS path, deployment credentials, or installer publishing process is compromised, the remote script can be replaced with arbitrary commands. Those commands would execute with the permissions of the user following the installation instruction.
Installing a CLI may be necessary for the connector-based design, but immediate execution of an unpinned remote payload exceeds the minimum privileges and trust required to perform the declared dictionary lookup. The audited project supplies no fixed release version, checksum, signature, or local installer copy.
Attack Path
- The
ooCLI is absent, and the user follows the first-time setup instruction. - An attacker compromises or otherwise gains control over the content returned by
https://cli.oomol.com/install.sh. curlretrieves the attacker-controlled script.- The pipe sends the response directly to Bash without verification or review.
- Bash executes the payload with the invoking user's privileges.
- The payload can read accessible data, alter files, install additional software, or establish persistence.
Impact Assessment
Successful exploitation provides arbitrary command execution within the invoking user's security context. The attacker could access local files and credentials available to that user, modify user-owned configuration or ex ...[truncated 354 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Prefer a trusted operating-system package manager and pin the CLI to an exact reviewed version.
- If a standalone installer is required, download a versioned artifact to disk before execution.
- Publish and require verification of a pinned cryptographic checksum and, preferably, a signature tied to a documented signing key.
- Keep installation separate from autonomous Skill execution and require explicit user approval before running any installer.
- Display the artifact source, version, checksum, requested privileges, and expected changes before execution.
- Document a manual inspection procedure and provide reproducible release artifacts.
- Remove the direct
