T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:91- Finding
Unverified Remote Installer Execution Through Shell Pipelines
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:91-95
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup instructions pipe remotely retrieved content directly into command interpreters. The Unix command sends the response from
curltobash, while the Windows command passes the response fromInvoke-RestMethod(irm) toInvoke-Expression(iex).Neither instruction pins an immutable installer version nor verifies a cryptographic signature or checksum before execution. Consequently, the code ultimately executed can change after the Skill has been reviewed. Although installation is presented as a fallback for a missing
ooCLI, executing a mutable remote installer is not the minimum privilege necessary to retrieve financial data through the declared connector.No malicious installer content is embedded in the reviewed project, and the trustworthiness of the remote scripts cannot be established from
SKILL.md. The vulnerability is the unauthenticated-at-the-artifact-level remote execution channel rather than confirmed malicious behavior by the current installer.Attack Path
- The
oocommand is unavailable, causing the first-time setup instructions to be used. - An agent or user runs the documented installation command.
- The command retrieves a mutable script from
cli.oomol.com. - An attacker who compromises the hosting account, deployment pipeline, domain, or another relevant delivery component substitutes malicious script content.
- The shell executes the substituted content immediately without checksum, signature, or manual-content verification.
- The payload performs arbitrary actions under the privileges of the us ...[truncated 822 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation patterns. - Distribute the CLI through a trusted package manager or an authenticated official release repository.
- Pin installation instructions to a specific immutable release rather than a mutable installer endpoint.
- Download the installer or package to a local file before execution so it can be inspected.
- Publish a cryptographic checksum and a verifiable digital signature through an independent trusted channel.
- Verify both the checksum and signature before invoking any interpreter or installer.
- Require explicit user approval before installing software; an agent should not automatically execute setup commands after a tool failure.
- Document the files, network destinations, and permissions required by the installer, and avoid administrator privileges unless a specific operation requires them.
- Prefer instructions similar to the following controlled sequence:
bash curl --fail --show-error --location \ --output oo-installer.sh \ "https://trusted.example/releases/vX.Y.Z/oo-installer.sh" echo "<published-sha256> oo-installer.sh" | sha256sum --check - # Verify the publisher's digital signature as well. less oo-installer.sh bash oo-installer.shThe actual release URL, checksum, and signature must come from an authenticated official source and must be pinned to the intended release.
- Remove direct
