T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Installer Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s GenderAPI.io behavior is mostly coherent, but its fallback setup tells users or agents to run an unverified remote installer directly in a shell.
Review the installer path before use. Prefer installing oo from a trusted, versioned source with checksum or signature verification, and do not run the pipe-to-shell commands unless you accept that the remote installer will execute with your local user privileges. The GenderAPI.io lookup actions themselves appear scoped to the stated service.
SKILL.md:57Unverified Remote Installer Download and Execution
The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses integrity verification and makes execution dependent on the current contents of a remote endpoint; if that endpoint, transport, or distribution pipeline is compromised, arbitrary code could run on the host. In this skill context, the risk is elevated because the instruction is embedded as an operational fallback, making it more likely to be executed during routine use.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
No suspicious patterns detected.