T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Shell Script Execution via curl and Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a mutable script from an external URL and passes the response directly to Bash. It does not pin an installer version, verify a cryptographic signature or checksum, save the script for inspection, or constrain the commands that the script may execute.
HTTPS protects the connection in transit under normal conditions, but it does not establish that every future script served by the endpoint is the same script reviewed during this audit. The effective payload remains outside the audited project and may change at any time. Compromise of the hosting infrastructure, publishing account, domain, or installer distribution process would allow arbitrary commands to be supplied to users following this instruction.
Installing the required CLI supports the Skill's functionality, but immediate execution of an unverified network response exceeds the minimum safe privilege necessary. A pinned and authenticated installation mechanism could provide the same functionality with lower risk.
Attack Path
- The
ooCLI is absent, causing anoo: command not foundfailure. - The agent or user follows the fallback installation instruction in
SKILL.md. - The command retrieves the current response from
https://cli.oomol.com/install.sh. - The response is passed directly to Bash without integrity verification or review.
- If the remote endpoint or release process has been compromised, attacker-controlled shell commands execute with the privileges of the invoking user.
- Those commands may access local files and credentials, modify user-level configuration, establish persistence, or retrieve additional payloads, subject to the invoking account's pe ...[truncated 542 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Prefer a signed platform package manager or a pinned release artifact from an authenticated release channel.
- Pin an exact CLI version rather than retrieving a mutable latest installer.
- Download the artifact to disk before execution and verify a publisher signature and documented SHA-256 checksum.
- Fail closed when verification does not succeed.
- Present the source, version, expected permissions, filesystem changes, and network behavior to the user before installation.
- Require explicit user approval before executing any installer.
- Run installation with the least-privileged account possible and avoid requesting administrator privileges unless strictly required.
- Remove the direct
