T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60-64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from an external server and execute them immediately using Bash or PowerShell. They do not pin a release, verify a cryptographic checksum or signature, or give the user an opportunity to inspect the downloaded content before execution.
Installing the
ooCLI supports the Skill's declared Freshservice connector functionality, and the scripts are hosted on an OOMOL domain. However, direct pipe-to-shell execution exceeds the minimum necessary installation behavior because the same installation can be performed through a separately downloaded, authenticated, and explicitly approved artifact.The effective code executed is not contained in the audited project and can change after review. Compromise of the installation server, hosting account, delivery infrastructure, or downloaded script could therefore turn the documented fallback installation procedure into arbitrary code execution.
Attack Path
- The
oocommand is unavailable, causing the Agent or user to follow the first-time installation instructions. - An attacker compromises or gains the ability to alter the remote installation script or its delivery path.
curlor PowerShell downloads the attacker-controlled script.- The shell executes the response immediately without integrity or authenticity verification.
- The payload performs arbitrary actions using the invoking process's privileges.
Impact Assessment
Successful exploitation permits arbitrary command execution with the privileges of the user or Agent running the in ...[truncated 468 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace pipe-to-shell commands with installation through a trusted package manager or a version-pinned release artifact.
- Download the installer to a local file without executing it automatically.
- Publish and require verification of a cryptographic signature or checksum obtained through an authenticated channel.
- Pin the CLI version and immutable artifact URL so the reviewed payload cannot change silently.
- Display the artifact source, expected digest, requested privileges, and intended changes before installation.
- Require explicit user approval before executing any installer.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Document that Freshservice action payloads and responses transit the OOMOL connector so users can make informed decisions about sending potentially sensitive ticket data.
