T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:66- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 66–70
Vulnerability Type: Remote mutable code retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from an external server and immediately execute them using Bash or PowerShell. Neither installation path pins a script version, validates a cryptographic checksum or publisher signature, nor allows inspection before execution.
HTTPS protects the connection in transit but does not ensure that the returned script is safe. If the OOMOL website, DNS, CDN, TLS infrastructure, deployment pipeline, or publisher account is compromised, an attacker can replace the installation script with arbitrary code. The effective payload can also change after the Skill package has been reviewed.
Directly piping
curlintobashand pipingInvoke-RestMethodintoInvoke-Expressioncreate equivalent remote-code-execution channels. Installing the CLI this way is not necessary for the Skill's declared Enigma operations and exceeds the minimum privileges required to document or invoke the connector.Attack Path
- The user or Agent attempts to use the Skill on a system where the
ooCLI is unavailable. - The documented fallback instructs the user or Agent to execute one of the remote installation commands.
- An attacker compromises or gains control over the remote script delivery infrastructure, including the origin server, deployment account, DNS, or CDN.
- The server supplies an attacker-controlled script instead of the expected installer.
- Bash or PowerShell executes the response immediately without integrity or authenticity verification.
- The payload runs with the privileges of the invoking user and may inspect files, steal credentials ...[truncated 1134 chars]
- The user or Agent attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove both download-to-shell installation commands from the Skill instructions.
- Treat CLI installation as a separate, user-controlled prerequisite rather than an automatic fallback performed during Skill execution.
- Prefer a reputable operating-system package manager or an official signed package, pinned to an explicit version.
- If direct artifact downloads are unavoidable:
- Use an immutable, versioned release URL.
- Download the artifact to disk without executing it.
- Publish and verify a SHA-256 or stronger cryptographic digest through a separately protected channel.
- Verify a trusted publisher signature before execution.
- Display the source, version, and requested actions to the user.
- Obtain explicit user approval before running the verified installer.
- Do not execute installers with administrative privileges unless installation genuinely requires them and the user has explicitly approved the elevation.
- Document the minimum required filesystem, network, and account permissions.
- For automated environments, use a preinstalled, integrity-verified CLI image or package with a locked version and controlled provenance.
A safer conceptual workflow is:
bash # Download an immutable, versioned artifact without executing it. curl -fSLo oo-installer.sh "https://trusted.example/releases/<pinned-version>/install.sh" # Compare against a separately published expected digest. sha256sum oo-installer.sh # Inspect and execute only after verification and explicit user approval. less oo-installer.sh bash oo-installer.shThe actual implementation should use the vendor's official signed and version-pinned distribution mechanism rather than the placeholder URL shown above.
