T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63–67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from an external server and pass their contents directly to a command interpreter. The Unix command pipes the response into
bash, while the Windows command usesInvoke-Expressionthrough theiexalias.Neither command pins an installer version, verifies a cryptographic signature or checksum, nor permits inspection before execution. HTTPS protects data in transit under normal conditions, but it does not mitigate compromise of the hosting service, publishing account, certificate infrastructure, or installer build pipeline. The effective code executed can also change after the Skill has been reviewed.
This capability exceeds the minimum privileges required for the Skill's normal DNSFilter read operations. The document states that the CLI should be assumed to be installed already and presents installation only as a fallback after a command-not-found error. The network transfer performed by
oo connector runis otherwise consistent with the declared connector functionality, and the reviewed file contains no evidence of unrelated credential collection or hidden exfiltration.Attack Path
- The agent attempts to invoke
ooand receives anoo: command not founderror. - The agent follows the fallback installation instructions in
SKILL.md. - The command retrieves the current installer from
cli.oomol.comwithout verifying its identity or integrity. - If the remote host, publishing account, delivery path, or installer pipeline has been compromised, an attacker supplies modified script content.
- The p ...[truncated 816 chars]
- The agent attempts to invoke
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation patterns. - Prefer a trusted operating-system package manager or signed distribution channel.
- Pin the CLI to a reviewed, immutable version rather than downloading a mutable installer endpoint.
- If manual installation is required, download the installer to a local file first, verify a publisher signature or a checksum obtained through an independent trusted channel, and inspect it before execution.
- Require explicit user approval before installing software; do not allow an agent to install the CLI automatically after a command failure.
- Run installation with the lowest privileges possible and explicitly warn users not to use an elevated shell unless installation genuinely requires it.
- Document the expected artifact name, version, checksum, signer identity, and verification commands for both supported platforms.
- Remove direct
