T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve installer scripts from external URLs and immediately pass their contents to
bashor PowerShell'sInvoke-Expression. The payload is not pinned to an immutable release and is not subjected to checksum, signature, or publisher verification before execution.Although HTTPS protects the scripts while in transit, it does not prevent malicious execution if the distribution server, hosting account, DNS infrastructure, certificate issuance process, or published installer is compromised. It also does not ensure that the payload audited today is the payload served later. The downloaded scripts are absent from the project, so their behavior and required privileges cannot be independently reviewed.
This installation behavior exceeds the minimum privileges required for ordinary ExpoFP connector operations. Those operations only require an already installed
ooCLI and commands matchingoo connector ...; arbitrary remote shell execution is needed only for optional installation. The risk is partially reduced because the documentation says installation should occur only after an actualoo: command not foundfailure, but execution remains unverified.Attack Path
- The
ooCLI is unavailable and an agent or user follows the documented first-time setup. - An attacker compromises or gains control over the installer endpoint or its delivery infrastructure.
- The endpoint serves a modified shell or PowerShell payload.
curl | bashorirm | iexexecutes that payload immediately without local review or inte ...[truncated 1143 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove instructions that pipe network responses directly into a command interpreter.
- Pin the CLI to a specific, reviewed release rather than a mutable installer URL.
- Download the installer or binary to a local file without executing it automatically.
- Verify a publisher signature or a cryptographic checksum obtained through an independently protected channel.
- Prefer signed packages distributed through a trusted operating-system package manager.
- Allow the user to inspect the downloaded artifact and require explicit approval before execution.
- Run installation with ordinary user privileges unless a specific, documented step strictly requires elevation.
- Document the files, network destinations, and system changes made by installation.
- Keep installation outside the Skill's automated execution path; retain the existing requirement that setup only be offered after a genuine missing-command error.
