T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Execution via Shell Pipeline
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from external URLs and immediately pass their contents to command interpreters. Neither installation path pins a release nor verifies a cryptographic signature or checksum before execution.
HTTPS provides transport protection but does not establish that the retrieved script is the same artifact that was reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, or upstream build process could alter the effective payload after this Skill has been audited.
The installation behavior supports the Skill's declared dependency on the
ooCLI, but direct remote-to-shell execution exceeds the minimum privilege and trust necessary to install that dependency. A safer process can download a fixed release, authenticate it, and request explicit approval before execution.Attack Path
- A Gladia action fails because the
ooCLI is not installed. - The user or agent follows the documented first-time setup instructions.
- The system retrieves the current contents of
install.shorinstall.ps1. - The downloaded content is executed immediately without inspection or integrity verification.
- If the remote source or distribution chain has been compromised, attacker-controlled commands execute with the privileges of the invoking user.
- Those commands may access user-readable data, modify files, install additional software, or establish persistence, depending on host permissions and the installer execution context.
Impact Assessment
Successful exploitation pro ...[truncated 589 chars]
- A Gladia action fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove both direct execution pipelines (
curl | bashandirm | iex). - Direct users to an official package manager or a version-pinned release artifact.
- Download the installer or binary to a local file without executing it.
- Publish and verify a cryptographic signature from a separately distributed, trusted signing key. At minimum, verify a checksum pinned in the Skill to a specific release.
- Fail closed if signature or checksum validation does not succeed.
- Display the verified artifact path and request explicit user approval before execution.
- Avoid requiring administrator privileges unless a documented installation step strictly needs them.
- Document the exact version, expected publisher, destination paths, and filesystem or system changes made during installation.
- Apply equivalent integrity and approval controls to the macOS/Linux and Windows installation procedures.
- Remove both direct execution pipelines (
