T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:68- Finding
Unverified Remote Installer Retrieval and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 68–72
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from an external server and immediately execute them using Bash or PowerShell. Neither command pins a specific artifact version, verifies a cryptographic checksum or digital signature, nor gives the user an opportunity to inspect the downloaded script before execution.
HTTPS protects the network connection under normal conditions, but it does not establish that the current contents of a mutable installer are identical to those reviewed during this audit. Compromise of the distribution server, hosting account, DNS infrastructure, CDN, TLS signing chain, or installer publishing process could replace the script with arbitrary commands.
The installation operation also exceeds the minimum privileges needed for the Skill's declared Hacker News reading and searching functionality. Hacker News exposes public data, while installing and executing a third-party CLI introduces a general-purpose local code-execution channel. Although the instructions state that installation should only occur after a missing-command failure, this condition does not mitigate the integrity risk of the downloaded installer.
Attack Path
- The
oocommand is unavailable when the Skill is used. - The operator or agent follows the documented first-time setup fallback.
- An attacker compromises or gains control over the remotely hosted installer or its delivery infrastructure.
- The attacker modifies
install.shorinstall.ps1to contain malicious commands. curl | bashorirm | iexpasses the response directl ...[truncated 814 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove all pipe-to-shell installation instructions, including both
curl | bashandirm | iex. - Distribute the CLI through a trusted package manager or provide a version-pinned installer artifact.
- Publish a cryptographic checksum and, preferably, a verifiable digital signature for every installer release.
- Require users to download the artifact separately, verify its signature or checksum, inspect it when appropriate, and then execute it as an independent step.
- Require explicit user approval before installing software; an agent should never initiate installation automatically merely because a command is missing.
- Document the exact installer version, expected publisher, requested permissions, installation destination, and files or services that will be modified.
- Run installation with standard-user privileges wherever possible and request elevation only for a narrowly defined operation that genuinely requires it.
- Consider using Hacker News's public interfaces directly for read-only functionality, avoiding installation of a general-purpose intermediary CLI when it is not essential.
- Remove all pipe-to-shell installation instructions, including both
