T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:55- Finding
Unverified Remote Shell Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction retrieves a mutable shell script from an external server and immediately pipes it into Bash. The payload is not pinned to a specific release, saved for inspection, or verified using a cryptographic checksum or publisher signature.
HTTPS protects the payload in transit but does not protect users if the hosting service, deployment pipeline, DNS infrastructure, or publisher account is compromised. Because the remotely hosted script can change after this Skill has been reviewed, the command creates an external code-execution channel whose effective behavior cannot be determined from the audited package.
Installing the CLI may be relevant when it is absent, but immediate execution of unverified remote content exceeds the minimum privilege needed to provide installation guidance. A versioned and integrity-verified installation process would satisfy the same purpose without delegating arbitrary shell execution to a mutable URL.
Attack Path
- An action fails because the
ooCLI is not installed. - The user or agent follows the documented first-time setup instruction.
curldownloads the current content ofhttps://cli.oomol.com/install.sh.- The downloaded bytes are passed directly to Bash without integrity verification or review.
- If the remote source or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the invoking account.
- Those commands can access user-readable data, alter files, install additional software, or establish persistence subject to the account's permissions.
Impact Assessment
Successful exploitation provides arbitrary command e ...[truncated 379 chars]
- An action fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation pattern. - Direct users to an official package manager or a versioned release artifact pinned to an explicit version.
- Download the installer to a separate file rather than executing it as a stream.
- Publish and verify a cryptographic signature or an independently distributed SHA-256 checksum before execution.
- Display or inspect the verified script before running it.
- Execute installation with ordinary user privileges and request elevation only for narrowly defined operations that require it.
- Document the expected files, network destinations, and configuration changes made by the installer.
- Remove the
