T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:66- Finding
Unverified Remote Installation Script Executed Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a script from an external URL and pipes it directly into Bash. The script is neither pinned to an immutable version nor validated using a cryptographic signature or checksum. Consequently, the code executed on the local system can change after the Skill has been reviewed.
HTTPS protects the connection in transit but does not guarantee that the hosting account, server, DNS configuration, or installation script remains trustworthy. Although installing the
ooCLI supports the Skill's declared functionality, immediate execution of mutable remote content is not the minimum safe installation method.Attack Path
- An attacker compromises the installation host, its deployment pipeline, hosting account, or another component capable of modifying
https://cli.oomol.com/install.sh. - The attacker replaces or modifies the installation script with malicious shell commands.
- The
oocommand is unavailable, causing the documented first-time setup path to be used. - The command downloads the attacker-controlled response and passes it directly to Bash.
- Bash executes the payload with the privileges of the user running the Agent.
Impact Assessment
Successful exploitation permits arbitrary command execution under the invoking user's account. Depending on that account's permissions and the payload, an attacker could read or modify local files, access environment variables and credentials, alter installed tools, exfiltrate sensitive information, or attempt persistence and further privilege escalation. The evidence does not establish that the current remote script is malicious, but the unverified execution channel ...[truncated 40 chars]
- An attacker compromises the installation host, its deployment pipeline, hosting account, or another component capable of modifying
- Remediation
View remediation
Remediation Suggestions
Remove the pipe-to-shell installation command. Install the CLI through a trusted package manager using a pinned version, or use the following controlled process:
- Download a versioned release artifact without executing it.
- Verify its SHA-256 checksum against a value delivered through a separately trusted channel.
- Verify a publisher signature where available.
- Inspect the downloaded installer before execution.
- Execute it without elevated privileges unless elevation is demonstrably required.
- Document the exact version and trusted release source so future audits evaluate an immutable artifact.
