T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installation Scripts Are Downloaded and Immediately Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61-65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions download mutable scripts from an external server and pass them directly to a command interpreter. Neither command pins a release version, verifies a cryptographic signature or checksum, nor saves the script for inspection before execution.
HTTPS protects the connection in transit but does not guarantee that the hosted payload is immutable or safe. If the download server, hosting account, DNS infrastructure, certificate issuance process, or release pipeline is compromised, the delivered script can be replaced after this Skill has been reviewed. The effective code executed by the user is therefore outside the audited project.
This installation mechanism is not required for routine Formbricks operations when the
ooCLI is already installed. Although the instructions limit it to first-time setup after anoo: command not founderror, arbitrary remote-script execution exceeds the minimum privileges required merely to install a known CLI artifact safely.Attack Path
- The user or Agent attempts to invoke
ooand receives anoo: command not founderror. - The Agent follows the documented first-time setup procedure.
- The shell retrieves the current contents of
install.shorinstall.ps1from the external OOMOL host. - The response is immediately interpreted by Bash or PowerShell without integrity verification or review.
- An attacker controlling or compromising the delivery infrastructure substitutes malicious script content.
- The substituted payload executes with the permissions of the user who launch ...[truncated 712 chars]
- The user or Agent attempts to invoke
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashandirm | iexinstallation patterns. - Direct users to a version-pinned release artifact hosted in the official release repository.
- Download the artifact to a local file without automatically executing it.
- Publish and require verification of a cryptographic signature or a trusted, version-specific SHA-256 checksum before installation.
- Execute the verified local installer only after verification succeeds.
- Prefer signed operating-system package repositories or platform-native package managers where available.
- Apply equivalent integrity controls to both the Bash and PowerShell installation paths.
- Document the files, permissions, and network endpoints used by the installer so users can assess the installation scope.
- Avoid requesting elevated privileges unless a specific installation step strictly requires them, and explain any such requirement before execution.
- Remove the direct
