T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Remote CLI Installer Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis Both installation commands retrieve mutable code from an external server and immediately execute it in a local command interpreter. Neither command pins a version, verifies a cryptographic signature, checks a known digest, nor gives the user an opportunity to inspect the downloaded script before execution. HTTPS authenticates the server connection under normal conditions, but it does not establish that the current script is identical to the version reviewed with this Skill. If the hosting domain, deployment pipeline, DNS resolution, TLS trust chain, or upstream account is compromised, the returned script can be replaced without any change to `SKILL.md`. The commands are documented as conditional first-time setup rather than routine execution, and the domain appears consistent with the declared OOMOL service. Nevertheless, source consistency does not eliminate the remote-code-execution boundary. Installing the CLI is also separate from the Skill's core read-only Contentstack operations and should not occur through an unverified execution pipeline. The connector commands elsewhere in the file necessarily transmit action payloads to the declared OOMOL/Contentstack connector service. The document states that credentials are injected server-side and does not expose raw tokens. Based on the available file, that declared network behavior is necessary for the Skill's functionality and is not independently classified as a vulnerability. ...[truncated 1699 chars]- Remediation
View remediation
/install.sh' ``` 4. Publish a version-specific SHA-256 digest or, preferably, a detached signature verified against a pinned vendor signing key. Verify it before execution: ```bash echo ' oo-install.sh' | sha256sum --check less oo-install.sh bash oo-install.sh ``` 5. Apply the equivalent controls on Windows: download a versioned script, validate an Authenticode signature or pinned cryptographic digest, allow inspection, and only then execute it. 6. Document the expected files, network destinations, and configuration changes made by the installer. 7. Explicitly instruct users not to run the installer as root or Administrator unless a documented operation strictly requires elevation. 8. Keep installation outside normal Skill execution. If `oo` is unavailable, return a clear prerequisite error rather than automatically retrieving or executing remote code. 9. Pin the CLI version used with the Skill and provide an authenticated update process so upstream changes cannot silently alter the reviewed execution path. ]]>
