T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63–67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand pass their contents directly to Bash or PowerShell. The scripts are executed without first saving them for inspection, pinning an immutable release, or verifying a cryptographic signature or digest.The installer files are not included in the audited project, so their contents and behavior cannot be assessed from the repository. Although the host is consistent with the declared OOMOL service, these commands establish an external code-execution channel whose effective payload can change after the Skill has been reviewed.
This capability exceeds what is necessary for routine DataScope operations. Normal use requires only the allowlisted
ooCLI commands, while the installation fallback can execute arbitrary commands with all permissions of the invoking user.Attack Path
- The
ooCLI is absent, causing the user or agent to follow the first-time setup instructions. - An attacker compromises the installer publication process, hosting infrastructure, domain resolution, or another trusted delivery component associated with
cli.oomol.com. - The attacker replaces or modifies
install.shorinstall.ps1with a malicious payload. curlorirmretrieves the attacker-controlled response.- The shell pipeline passes the response directly to Bash or PowerShell without integrity verification or inspection.
- The payload executes with the permissions of the invoking user.
Impact Assessment
Successful exploitation provides arbitrary code execution in the user context. The payload could read ...[truncated 546 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove all pipe-to-shell and download-to-
Invoke-Expressioninstallation instructions. - Prefer a trusted operating-system package manager or a formally published, version-pinned CLI package.
- If direct installation artifacts are necessary:
- Pin a specific immutable CLI release and artifact URL.
- Download the artifact to disk without executing it.
- Publish a SHA-256 digest or cryptographic signature through a separately authenticated channel.
- Verify that digest or signature before execution.
- Permit inspection and require explicit user approval before running the installer.
- Run installation with ordinary user privileges unless elevation is strictly necessary and clearly justified.
- Document the files, permissions, network destinations, and system changes expected from the installer.
- Keep installation outside automated Skill execution; the Skill should report the missing dependency and direct the user to verified manual installation documentation.
- Remove all pipe-to-shell and download-to-
