T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions pipe mutable content retrieved from an external server directly into Bash or PowerShell. The downloaded scripts are executed without version pinning, cryptographic signature verification, checksum validation, or an opportunity to inspect the content locally.
Although the source domain is consistent with the declared OOMOL service and installation is only suggested when the
oocommand is unavailable, direct remote-script execution exceeds the minimum privilege and trust necessary to install a CLI. The effective executable payload can change after this Skill has been reviewed.The behavior creates a supply-chain execution channel. A compromise of the installer host, publishing infrastructure, DNS resolution, or another relevant delivery component could cause arbitrary attacker-controlled commands to be returned and immediately executed.
Attack Path
- The
ooCLI is not installed, causing anoo: command not foundfailure. - The Agent or user follows the documented first-time setup instructions.
- The system requests
install.shorinstall.ps1fromcli.oomol.com. - The external response is passed directly to Bash or PowerShell without integrity or authenticity verification beyond transport security.
- If the remote installer or its delivery infrastructure is compromised, attacker-controlled commands execute immediately.
- Those commands operate with the ...[truncated 870 chars]
- The
- Remediation
View remediation
Remediation Suggestions
-
Remove the
curl | bashandirm | iexinstallation patterns. -
Direct users to a versioned release artifact or an official package manager with package-signing support.
-
Pin the CLI to a reviewed version rather than executing the latest mutable installer.
-
Publish cryptographic hashes or signatures through a separately protected channel and require verification before execution.
-
Download the installer to a local file first, verify its integrity and publisher, and permit inspection before running it.
-
Require explicit user approval before installing software; the Agent should not automatically perform installation after a command failure.
-
Run installation with ordinary user privileges whenever possible and clearly warn against using an elevated shell unless elevation is strictly required.
-
Prefer instructions similar to:
bash curl -fSLo oo-installer.sh "https://trusted.example/releases/VERSION/install.sh" echo "EXPECTED_SHA256 oo-installer.sh" | sha256sum --check less oo-installer.sh bash oo-installer.shThe real implementation must use an official versioned URL and a checksum or signature obtained from a trusted, independently protected source.
-
