T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for read-only Datadog access, but it routes monitoring data through OOMOL, broadly directs all Datadog work through that connector, and documents unsafe remote installer commands.
Install only if you intentionally want Datadog queries and results routed through OOMOL. Use a dedicated read-only Datadog key with minimum scopes, review OOMOL's credential and data-handling controls, and avoid running the documented remote installer commands unless you can verify the installer source and integrity.
SKILL.md:61Unverified Remote Installer Download and Immediate Shell Execution
SKILL.md:15Datadog Requests and Operational Data Are Routed Through a Third-Party Connector
SKILL.md:3Broad Instruction Forces All Datadog Requests Through the Vendor Connector
The skill instructs users to install software via a network-fetched shell script piped directly to bash, which executes remote content without prior verification. If the install endpoint, transport, or upstream distribution is compromised, this can lead to arbitrary code execution on the host running the skill setup.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Datadog request" and "Whenever a task involves Datadog," which is a very broad activation condition. It does not clearly bound when the skill should or should not be invoked, nor provide exclusions or negative examples.
No suspicious patterns detected.