T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56–60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from an external server and immediately execute their contents using Bash or PowerShell. Neither command pins a release, verifies a cryptographic checksum or signature, nor saves the script for inspection before execution.
HTTPS provides transport protection but does not establish that the retrieved script is the same artifact that was reviewed. Compromise of the hosting server, publishing account, DNS or delivery infrastructure—or an unintended change to the installer—could cause arbitrary new code to execute without requiring any modification to this Skill.
Installation is presented only as a fallback when the
ooCLI is unavailable. Installing the CLI may support the declared FlowiseAI integration, but executing an unverified remote response is not the minimum privilege or minimum-risk mechanism required to perform that installation.The separate connector commands in
SKILL.mdtransmit action payloads to the declared FlowiseAI integration through OOMOL. That network behavior is disclosed and functionally relevant, and the reviewed file contains no evidence that raw credentials are deliberately collected or sent to an unrelated endpoint.Attack Path
- The
ooCLI is absent, causing the first-time setup instructions to apply. - A user or agent runs one of the documented installation pipelines.
- The command requests the current installer from
cli.oomol.com. - An attacker who has compromised the remote publishing or delivery path substitutes malicious script content.
- Bash o ...[truncated 877 chars]
- The
- Remediation
View remediation
Remediation Suggestions
-
Remove the direct
curl | bashandirm | iexexecution pipelines. -
Prefer a trusted platform package manager or an official, versioned release artifact.
-
Pin the CLI to a specific reviewed version rather than retrieving a mutable latest installer.
-
Download the artifact to a local file without executing it immediately.
-
Verify a publisher signature or a cryptographic checksum obtained through an independently authenticated channel.
-
Display the source, destination, requested permissions, and intended changes before installation.
-
Require explicit user approval before executing the verified installer.
-
Run installation without administrative privileges unless a documented operation strictly requires elevation.
-
If an installer script remains necessary, use a workflow such as:
bash curl -fSLo oo-install.sh "https://trusted.example/releases/vX.Y.Z/install.sh" echo "EXPECTED_SHA256 oo-install.sh" | sha256sum --check - less oo-install.sh bash oo-install.sh -
Publish and verify signed release manifests so integrity validation does not depend solely on the same server that hosts the installer.
-
