T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:69- Finding
Unverified Remote Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 69–73
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from an external URL and execute them immediately using Bash or PowerShell. Neither command pins a release version, validates a cryptographic checksum or signature, nor saves the script for inspection before execution.
HTTPS protects the connection in transit under normal conditions, but it does not establish that the retrieved script is the same artifact that was reviewed. If the OOMOL domain, DNS configuration, certificate infrastructure, hosting environment, or installer publication process is compromised, the remote script can be replaced without modifying this skill package.
Installing the CLI may be necessary for the declared Folk integration, but direct pipe-to-shell execution is not the minimum privilege or minimum-risk installation mechanism necessary. Installation also occurs outside the restricted
oocommand surface declared by the skill and permits the downloaded payload to execute arbitrary commands with the invoking user's privileges.The project does not contain the installer itself, so the installer's exact behavior cannot be verified from the audited artifact.
Attack Path
- The
ooexecutable is unavailable, causing anoo: command not founderror. - The user or agent follows the documented first-time setup procedure.
- Bash retrieves
install.shthroughcurl, or PowerShell retrievesinstall.ps1throughInvoke-RestMethod. - The downloaded response is passed directly to a command interpreter without integrity or authenticity verification beyond HTTPS.
- A compromised or malicio ...[truncated 1018 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-shell installation commands from agent-executable instructions.
- Direct users to a version-pinned release hosted through an official, auditable distribution channel.
- Download the installer or package to a local file without executing it immediately.
- Publish SHA-256 or stronger checksums through a separately protected channel and require verification before execution.
- Prefer signed packages and verify the publisher's cryptographic signature using a pinned, trusted public key.
- Display the resolved artifact version, source URL, checksum, and intended changes before requesting explicit user approval.
- Run installation with ordinary user privileges and avoid automatic elevation. If elevated access is genuinely necessary, document each privileged operation and request approval separately.
- Keep dependency installation outside autonomous skill execution. The skill should fail safely and provide manual installation guidance rather than execute remotely retrieved code.
- Pin the CLI version used by the skill and define a controlled, separately reviewed upgrade process.
