T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:80- Finding
Unverified Remote Bash Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 80
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command pipes a remotely retrieved script directly into Bash. The payload is neither version-pinned nor verified using a cryptographic checksum or digital signature, and users have no opportunity to inspect it before execution. Consequently, the effective code can change after the Skill has been reviewed.
Installation of the
ooCLI supports the declared HubSpot connector functionality, and the script is hosted on an OOMOL domain. Nevertheless, immediate execution of mutable network content is not the minimum safe installation mechanism. Compromise of the hosting service, its deployment process, or the network trust path could turn the documented setup procedure into arbitrary local code execution.Attack Path
- The
ooCLI is unavailable, causing anoo: command not founderror. - The agent or user follows the first-time setup instructions in
SKILL.md. - An attacker compromises or replaces the content served from
https://cli.oomol.com/install.sh, or otherwise subverts the trusted delivery path. curlretrieves the attacker-controlled script.- The shell pipeline passes the response directly to Bash without integrity verification or review.
- The payload executes with the privileges of the user running the command.
Impact Assessment
A malicious installer could run arbitrary commands with the invoking user's privileges. This may permit access to that user's files, environment variables, local application credentials, shell configuration, and accessible HubSpot-related data. It could also alter executables or configuration, download further payloads, or establish persistence where the user's permissions allow it. The instruction doe ...[truncated 205 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace the pipe-to-shell installation method with a version-pinned package or downloadable release artifact.
- Publish cryptographic checksums and signed release metadata through a separately authenticated channel.
- Download the artifact to disk, verify its checksum and signature, and only then execute or install it.
- Pin the installer or CLI to an audited version rather than retrieving mutable content from a generic installation URL.
- Document the expected files, permissions, network connections, and configuration changes made by the installer.
- Require explicit user approval before installation and do not let the agent perform unattended installation automatically.
- Prefer the operating system's trusted package manager where supported.
