T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61-65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup instructions retrieve mutable scripts from
cli.oomol.comand immediately execute them through Bash or PowerShell. They do not pin an installer version, verify a cryptographic checksum or publisher signature, save the script for inspection, or otherwise validate its integrity before execution.HTTPS provides transport protection but does not establish that the remotely served script remains identical to the artifact that was reviewed. Compromise of the hosting origin, deployment pipeline, associated account, CDN, or another trusted delivery component could cause arbitrary replacement code to execute.
Installing the CLI may be relevant when it is unavailable, but direct execution of an unverified remote script is not the minimum privilege or safest mechanism required for the Skill's declared read-only Gigasheet operations. It also falls outside the Skill's declared
Bash(oo *)runtime tool boundary.Attack Path
- The
ooCLI is unavailable and an authentication or connector action consequently fails. - The user or agent follows the documented first-time setup instructions.
- The command downloads the current installer from the remote OOMOL endpoint.
- A compromised server or software-delivery path supplies attacker-controlled script content.
- The shell executes that content immediately without integrity verification or review.
- The payload performs arbitrary actions under the privileges of the user running the command and may retrieve additional payloads.
Impact Assessment
A substituted installer can obtain arbitrar ...[truncated 756 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation pipelines. - Prefer a trusted platform package manager and pin the CLI to a reviewed version.
- If a standalone installer is required, download a versioned artifact to disk without executing it automatically.
- Publish and verify a pinned SHA-256 checksum and a cryptographic publisher signature before execution.
- Display the verified installer location and require explicit user approval before running it.
- Keep dependency installation outside autonomous Skill execution and retain the declared
Bash(oo *)least-privilege boundary. - Document the expected publisher identity, release source, version, checksum, and signature-verification procedure.
- Fail closed if any integrity or authenticity check is unavailable or unsuccessful.
- Remove the
