T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from external URLs and immediately execute them with Bash or PowerShell. Neither command pins an audited release nor verifies a cryptographic signature or checksum before execution.
Consequently, the code that ultimately runs is controlled by the remote server at execution time and can differ from what was available when the Skill was reviewed. Compromise of the download server, publication pipeline, domain, or TLS trust path could result in arbitrary commands being supplied to the shell.
Installing the CLI is only a fallback when
oois unavailable and is not required for normal Dovetail connector operations. Automatic remote installation therefore exceeds the minimum privileges needed during an ordinary Skill invocation.Attack Path
- The
oocommand is unavailable, causing the agent or user to follow the first-time setup instructions. - An attacker compromises the installer endpoint, its deployment pipeline, or another component of the delivery trust chain.
- The attacker replaces the expected installer with a malicious shell or PowerShell payload.
curl | bashorirm | iexexecutes the payload immediately, without prior inspection or integrity verification.- The payload performs arbitrary actions with the privileges of the account running the command.
Impact Assessment
Successful exploitation provides arbitrary code execution under the invoking user's privileges. Depending on those privileges and the host configuration, the payload could read or modify accessible files, steal locally available credentials, alter tools or conf ...[truncated 296 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-shell installation commands.
- Require explicit user approval before installing software; the Skill should not perform installation automatically.
- Pin the CLI to a specific audited release and download the installer or binary to a local file before execution.
- Publish and verify a cryptographic signature or trusted SHA-256 checksum over the downloaded artifact.
- Display the artifact source, version, destination, and requested permissions before installation.
- Prefer a trusted platform package manager or signed release package where available.
- Run installation with ordinary user privileges unless elevated privileges are demonstrably required.
- Keep installation separate from routine connector execution so normal Dovetail operations retain the declared
Bash(oo *)least-privilege boundary.
