T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62-66
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
These installation commands retrieve mutable scripts from an external server and immediately pass their contents to Bash or PowerShell. They do not pin a version, validate a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded payload before execution.
HTTPS protects the connection in transit but does not guarantee that the hosted installer is safe or immutable. Compromise of the domain, hosting environment, CDN, deployment credentials, or installation script could cause arbitrary attacker-controlled code to execute. The effective payload can also change after the Skill has been reviewed.
Arbitrary shell execution exceeds the minimum permissions needed for the declared functionality, which is limited to invoking a Deepgram connector through an installed CLI.
Attack Path
- The
ooCLI is unavailable on the target system. - A user or agent follows the documented first-time setup instructions.
- An attacker compromises the installer distribution path or otherwise causes the remote endpoint to return a malicious script.
curlorirmdownloads the attacker-controlled content.- The pipeline passes that content directly to Bash or PowerShell without integrity verification.
- The payload executes with the privileges of the user running the command.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's account. Depending on that account's privileges, the payload could read or alter accessible files, steal credentials and environment dat ...[truncated 179 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove all download-and-immediately-execute installation commands.
- Prefer an official package manager and pin the CLI to an audited version.
- If a standalone installer is necessary, download it to a local file without executing it.
- Publish and verify a cryptographic checksum or signature from an independent trusted channel before execution.
- Allow users to inspect the downloaded script before running it.
- Execute installation with ordinary user privileges unless a narrowly defined step explicitly requires elevation.
- Pin installation URLs to immutable, versioned artifacts rather than mutable
install.shorinstall.ps1endpoints.
