T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Remote Shell Script Downloaded and Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for using Insites through OOMOL, but its setup instructions include unverified remote installer execution that users should review carefully.
Before installing, review the oo CLI installation path carefully. Prefer a signed or package-manager installation, avoid running the installer elevated, and verify what it downloads before execution. Once installed, reads are low risk, but confirm the exact payload before starting any Insites audit because that action changes account state.
SKILL.md:58Remote Shell Script Downloaded and Executed Without Verification
SKILL.md:62Remote PowerShell Script Downloaded and Executed Without Verification
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a code execution path from an external server without integrity verification, so if the hosting endpoint, transport, or distribution chain is compromised, arbitrary code could run on the user's machine.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Insites request" and "Whenever a task involves Insites," which is extremely broad and lacks boundaries or exclusion conditions. This can overlap with many routine mentions of Insites and does not specify when the skill should not activate.
No suspicious patterns detected.