T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified macOS and Linux installer is piped directly into Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a mutable shell script from an external URL and sends it directly to Bash. The project does not pin the installer to a specific version or verify a cryptographic signature or checksum before execution. Consequently, the code ultimately executed can change after this Skill has been reviewed.
The domain is consistent with the declared OOMOL provider, but domain consistency alone does not establish the integrity of every future response. A compromise of the hosting infrastructure, installer publication process, DNS or TLS trust chain could replace the expected installer with arbitrary shell commands.
This behavior exceeds the minimum privileges required for the Skill's declared connector functionality. The Skill can invoke an already-installed
ooCLI without executing a remotely controlled installation script. Installation should remain a separate, user-controlled operation with verifiable artifacts.Attack Path
- The
oocommand is unavailable, causing the user or Agent to consult the first-time setup instructions. - An attacker compromises the remote installer, its publication infrastructure, or a relevant network trust dependency.
curlretrieves the attacker-controlled response from the installer URL.- The pipe passes the response directly to Bash without saving, reviewing, pinning, or validating it.
- Bash executes the supplied commands with the privileges of the invoking user.
- The payload can access data and resources available to that user and may attempt additional privilege escalation if the environment permits it.
Impact Assessment
Successful exploitation provide ...[truncated 576 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation instruction from the Skill. - Direct users to a version-pinned release artifact from the official distribution channel.
- Require the artifact to be downloaded as a separate step rather than executed from a network stream.
- Publish a cryptographic checksum or signature through an independently protected channel and verify it before execution.
- Allow the user to inspect the downloaded installer before running it.
- Prefer a trusted package manager with version pinning and package-signature validation where available.
- Do not let the Agent install the CLI automatically; require an explicit, informed user decision.
- Run installation with ordinary user privileges unless a narrowly defined operation demonstrably requires elevation.
- Remove the
