T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Shell Script Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions pipe a remotely retrieved installation script directly into
bash. The content is executed without being displayed, reviewed, pinned to a specific release, or verified using a cryptographic signature or trusted checksum.Although installation is presented as a fallback for a missing
ooCLI rather than an automatic step, direct execution of mutable remote content creates a time-of-check/time-of-use supply-chain boundary: the script delivered during installation may differ from the content assessed when this Skill was reviewed. HTTPS protects the connection in transit but does not protect against compromise of the hosting service, publishing account, build pipeline, DNS/control plane, or upstream installation artifacts.Installing the CLI is ancillary setup rather than part of the Skill's declared Hyperbrowser operations. Executing an unrestricted remote shell script therefore exceeds the privileges required to run the documented
oo connector schemaandoo connector runcommands.Attack Path
- The
ooexecutable is absent, causing a command-not-found failure. - The Agent or user follows the documented first-time installation fallback.
- An attacker compromises the remote script, its publishing pipeline, or the infrastructure serving it.
curlretrieves the attacker-controlled response.- The pipe passes the response directly to
bashwithout inspection or integrity validation. - The payload executes with the privileges of the Agent or user running the command.
Impact Assessment
A malicious installer can execute arbitrary shell commands with the invoking account's privileges. Depending on that a ...[truncated 464 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Do not pipe network responses directly into a shell.
- Link to a documented, manually initiated installation process rather than instructing the Agent to execute the installer.
- Pin the CLI to an explicit release version hosted on a trusted release channel.
- Download the installer or package to a local file first.
- Verify a publisher signature and a cryptographic checksum obtained through an independently authenticated channel.
- Inspect the verified artifact before executing it as a separate command.
- Request explicit user approval before performing software installation or privilege elevation.
- Prefer a signed operating-system package with narrowly scoped permissions and documented provenance.
