T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:65- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 65–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand immediately pass their contents to Bash or PowerShell. The downloaded payload is not displayed for review, pinned to a specific version, checked against a cryptographic digest, or authenticated with a verifiable signature.Consequently, the code that executes can differ from the content available when this Skill was audited. Compromise of the download server, hosting infrastructure, publishing credentials, DNS resolution, TLS termination, or release process could turn these installation commands into an arbitrary-code-execution channel.
Installing the
ooCLI is ancillary setup rather than part of the Skill's routine Habitica functionality. Automatic execution of a mutable installer therefore exceeds the minimum privileges needed to issue the documented connector commands. Although the instructions only recommend installation after anoo: command not foundfailure, they still expose any user or agent following that fallback to the remote payload.No evidence in the reviewed file establishes that the current remote scripts are malicious, and the package contains no local executable scripts. The vulnerability arises from trusting and executing future remote content without independent verification.
Attack Path
- An attacker compromises the installer host, publishing process, DNS path, or another component capable of changing the response from
https://cli.oomol.com/install.shorinstall.ps1. - The
oocommand is unavailable, causing the documented first-time setup condition to occur. ...[truncated 1204 chars]
- An attacker compromises the installer host, publishing process, DNS path, or another component capable of changing the response from
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-interpreter installation commands.
- Direct users to a documented manual installation flow or a trusted platform package manager.
- Pin the CLI to an explicit release version rather than downloading a mutable installer endpoint.
- Download the artifact without executing it, then verify a publisher-signed release and a checksum obtained through an independently authenticated channel.
- Display the verified script or package source and require explicit user approval before installation.
- Run installation with ordinary user privileges whenever possible; do not request administrator or root access unless a specific installation step requires it.
- Publish reproducible release artifacts and document the expected signing identity, checksum format, and verification commands.
- Keep CLI installation outside automated Skill execution. If the CLI is missing, report the prerequisite and allow the user to choose whether and how to install it.
