T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60-68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighThe first-time setup instructions execute remotely hosted installation scripts directly in a shell:
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
Both installation commands combine remote retrieval with immediate code execution. The downloaded scripts are not version-pinned, inspected, hash-verified, or authenticated using a detached signature. Consequently, the code ultimately executed can change after the Skill has been reviewed.
Although the scripts are hosted on an OOMOL domain and installation is presented only as a fallback when the
oocommand is unavailable, domain ownership alone does not establish the integrity of each downloaded payload. Compromise of the hosting infrastructure, deployment pipeline, domain, or trusted endpoint could cause arbitrary attacker-controlled commands to run. Thecurl -fsSLoptions affect transfer behavior but do not verify the script against a known-good artifact. The PowerShellirm ... | iexinstruction has the equivalent weakness.Installing the CLI may support the declared Eventzilla connector functionality, but immediate execution of a mutable network response exceeds the minimum privilege necessary. A verified, version-pinned installation mechanism can provide the same functionality without piping an unreviewed response directly into an interpreter.
Attack Path
- The
ooCLI is absent, and an operator or agent follows the documented fallback setup. - An attacker compromises the remote installer endpoint, its publishin ...[truncated 1144 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-interpreter installation commands from the Skill instructions.
- Direct users to a version-pinned package or release artifact obtained through an authenticated package manager or official release channel.
- If a standalone installer is necessary, download it to a local file without executing it:
- Use a fixed versioned URL.
- Publish a trusted SHA-256 digest and verify it before execution.
- Prefer a detached cryptographic signature whose verification key is distributed through a separate trusted channel.
- Abort installation if any integrity or signature check fails.
- Allow the user to inspect the downloaded installer and require explicit approval before executing it.
- Run installation with ordinary user privileges unless elevated access is demonstrably required. Do not embed automatic privilege elevation in the installer flow.
- Document the files, configuration changes, and network endpoints used by the installer.
- For automated environments, fail with a clear manual installation message instead of automatically retrieving and executing remote code.
