T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Executed Directly Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command downloads a mutable shell script from an external URL and pipes it directly into Bash. The remote content is executed without version pinning, checksum validation, digital-signature verification, local inspection, or a separate confirmation step.
Although this instruction is presented as first-time setup and uses the CLI vendor's domain, the effective code is not contained in the reviewed project. It can change after the skill has been audited. Compromise of the hosting service, release process, domain, or applicable TLS trust chain could therefore turn the documented installation step into arbitrary local code execution.
Installing the CLI may be necessary for the declared Fillout integration, but immediate execution of an unverified remote script exceeds the minimum privilege and trust required to distribute that CLI.
Attack Path
- The
oocommand is unavailable, causing the user or agent to consult the first-time setup instructions. - An attacker compromises or modifies the remote installer, its hosting infrastructure, release pipeline, domain resolution, or another relevant delivery component.
- The user executes the documented
curl ... | bashcommand. curlretrieves the attacker-controlled script and sends it directly to Bash without an opportunity for review or integrity verification.- Bash executes the payload with all privileges available to the invoking account.
Impact Assessment
A malicious installer can execute arbitrary commands with the invoking user's privileges. It could access or modify user-readable files, steal locally accessible credentials or session data, install additional ...[truncated 434 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Do not pipe downloaded content directly into a shell.
- Publish versioned CLI artifacts through a trusted package manager or a version-pinned release URL.
- Download the artifact to a local file before execution.
- Publish a cryptographic checksum and preferably a signature through an independently protected channel.
- Verify the checksum and signature before running the installer.
- Display the resolved version and source to the user and require an explicit installation decision.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Document the files, permissions, network destinations, and persistent changes made by the installer.
- Prefer a sequence such as download, verification, inspection, and separate execution rather than a single pipeline.
