T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from
https://cli.oomol.comand immediately execute their contents using Bash or PowerShell. No fixed version, cryptographic signature, checksum, or independent verification is required before execution.HTTPS protects the connection in transit under normal conditions, but it does not establish that the remotely hosted script is immutable or safe. Compromise of the distribution server, its deployment process, DNS or certificate infrastructure, or an authorized publishing account could cause arbitrary attacker-controlled commands to be returned and executed. The effective installation payload can also change after the Skill has been reviewed.
Installing the required CLI is related to the Skill's declared functionality, but direct pipe-to-shell execution exceeds the minimum privilege and trust necessary to perform that installation. A downloaded artifact can instead be pinned and authenticated before the user separately executes it.
Attack Path
- The
ooCLI is absent, causing the Skill's first-time setup instructions to become applicable. - An attacker compromises or otherwise gains control over the remote installation response delivered by
cli.oomol.com. - The user or Agent runs the documented
curl | bashorirm | iexcommand. - The shell interprets the response immediately, without giving the user an opportunity to inspect or authenticate it.
- The malicious script executes arbitrary commands with the privileges of the user running the installation command.
- The pa ...[truncated 986 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands from the Skill instructions.
- Direct users to a documented official package manager or a versioned release artifact hosted in an authoritative repository.
- Pin the CLI to a specific reviewed version rather than retrieving an unversioned installation script.
- Publish a SHA-256 checksum or, preferably, a cryptographic signature for every release artifact.
- Require users to download the artifact to disk, verify its signature or checksum, and execute it as a separate step.
- Provide platform-specific instructions that avoid unnecessary administrative privileges.
- If an installer script must be distributed, make its source auditable, pin its exact version or commit, authenticate it before execution, and clearly display the commands users are expected to run.
- Keep the existing behavior of attempting normal connector operations before presenting setup steps, so installation is not triggered unless the CLI is actually unavailable.
A safer high-level workflow is:
text Download a specific release artifact → verify its publisher signature and pinned checksum → inspect or install the verified artifact separately → run the CLI without elevated privileges unless explicitly required
