T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent Formsite connector, but its setup instructions include unverified remote install commands that can execute changing code on a user's machine.
Review this skill before installing. The Formsite operations themselves are clearly described and include user confirmation for writes and deletions, but do not run the documented remote installer commands unless you trust the OOMOL installer source and have a way to verify what will execute. Prefer an already installed, trusted oo CLI or a signed/version-pinned installation method.
SKILL.md:61Unverified Remote Installer Scripts Executed Directly by Shells
The skill instructs users to install software by piping a remote script directly into a shell (curl ... | bash). If the install endpoint, transport path, or hosting account is compromised, arbitrary code would execute immediately on the user's machine with the user's privileges, turning a setup failure into a full client-side code execution risk.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Formsite request" and "Whenever a task involves Formsite," which is extremely broad and overlaps with many ordinary requests involving Formsite. It does not provide trigger constraints, exclusions, or negative examples to clarify when the skill should or should not activate.
No suspicious patterns detected.