T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions pipe a mutable network response directly into Bash. The downloaded installer is not pinned to a reviewed version, saved for inspection, or validated using a cryptographic signature or trusted checksum.
Consequently, the code executed when the instruction is followed can differ from the content available during this audit. HTTPS protects the connection in transit under normal conditions but does not establish that the current server-hosted payload is the same payload that was previously reviewed. Compromise of the distribution server, its deployment process, DNS or certificate trust, or the vendor account controlling the script could turn this installation instruction into an arbitrary-code execution channel.
Installing the required CLI may be legitimate when
oois absent, but directly piping remote content into a shell exceeds the minimum safe installation mechanism. The project does not include the installer, so its behavior and requested privileges cannot be verified from the audited artifact.Attack Path
- The
ooCLI is unavailable, causing an agent or user to consult the first-time setup section. - An attacker compromises or gains control over
https://cli.oomol.com/install.sh, or otherwise causes that endpoint to return a malicious script. - The user or agent runs the documented command.
curlretrieves the current response and pipes it directly to Bash without integrity or authenticity verification.- Bash executes the attacker-controlled commands immediately.
- The payload can access resources available to the invoking account, modify user-writable files, install additional software, and initiate network c ...[truncated 668 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the pipe-to-shell installation command.
- Direct users to a version-pinned release artifact from an authenticated release channel.
- Download the artifact to disk before execution so that it can be inspected.
- Publish a cryptographic checksum through a separately authenticated channel and verify it before installation.
- Prefer signed packages and require verification of the publisher's signature.
- Require explicit user approval before executing any installer.
- Document the files, network destinations, and privileges used by the installer.
- Avoid administrative execution unless a specific installation operation requires it.
- If an installer script must be offered, use a workflow similar to:
bash curl -fL -o install.sh "https://trusted.example/releases/vX.Y.Z/install.sh" printf '%s %s\n' 'PUBLISHED_SHA256' 'install.sh' | sha256sum --check less install.sh bash install.shThe release URL and checksum must be version-specific and maintained through a trustworthy publication process.
