T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions download mutable scripts from an external server and immediately execute them using Bash or PowerShell. They do not pin a release version, save the script for inspection, validate a cryptographic checksum, or verify a digital signature.
HTTPS protects data in transit when its trust assumptions hold, but it does not establish that the current script is the same artifact that was security-reviewed. Compromise of the hosting infrastructure, domain or certificate control, deployment pipeline, or maintainer account could replace the script with arbitrary commands. Those commands would execute with all privileges available to the shell that invoked the installer.
Installing a CLI may be relevant to first-time setup, but immediate execution of unverified remote content exceeds the minimum privilege and trust necessary to install it. The documentation also correctly says installation should only be considered after a command-not-found failure, but it does not require explicit approval before executing the installer.
The skill's
upload_fileaction also sends user-selected source files through OOMOL to Crowdin. This network behavior is consistent with the declared Crowdin integration, and the skill requires confirmation for write actions; the reviewed file does not demonstrate covert exfiltration.Attack Path
- The
ooCLI is unavailable, causing the documented first-time setup condition. - A user or agent executes one of the provided installation commands.
- An attacker who has compromised the remote installation endpoint ...[truncated 1211 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation patterns. - Prefer an official package manager or a version-pinned release artifact from a verifiable distribution channel.
- Download the installer to a local file without executing it automatically.
- Publish and require verification of a cryptographic checksum and, preferably, a signature tied to a documented release-signing key.
- Display or inspect the downloaded script before execution, and require explicit user approval.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Pin the documented installer to a reviewed version instead of relying on mutable
install.shorinstall.ps1endpoints. - Document the files, network destinations, and system changes made by the installer.
- For example, use a workflow equivalent to:
bash curl -fSLo oo-install.sh "https://trusted.example/releases/vX.Y.Z/install.sh" echo "<published-sha256> oo-install.sh" | sha256sum --check - less oo-install.sh bash oo-install.shThe checksum must be obtained through a separately authenticated release process; placing an untrusted checksum beside the mutable installer would not provide meaningful protection.
- Remove direct
