T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent HotspotSystem read-only connector, but its first-time setup tells users or agents to execute mutable remote installer scripts directly in a shell.
Install only if you trust OOMOL and HotspotSystem access through this connector, and do not let an agent run the remote installer commands automatically. Prefer installing the oo CLI from a verified release or package source, review what it changes, then connect only the HotspotSystem account and scopes you intend the agent to read.
SKILL.md:61Unverified Remote Installer Downloaded and Executed Directly
The skill instructs users to install software by piping a remote script directly into a shell, which creates a supply-chain and remote-code-execution risk. If the install endpoint, transport, upstream distribution, or hosting account is compromised, arbitrary code would run immediately on the user's machine with the user's privileges.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY HotspotSystem request" and "Whenever a task involves HotspotSystem," which is an expansive activation condition that can overlap with many routine mentions of the product. It does not provide narrower trigger boundaries, exclusions, or negative examples to clarify when the skill should not activate.
No suspicious patterns detected.