T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installation Scripts Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56-64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
Both installation commands retrieve a mutable script from an external server and immediately execute it through a command interpreter. Neither command pins a release version nor verifies the payload using a cryptographic checksum or digital signature. The user or agent therefore cannot establish that the executed content is identical to the content reviewed when the Skill was published.
The instructions are conditional on the
oocommand being unavailable, rather than being part of every normal connector invocation. However, installing the CLI is ancillary setup, and executing an unverified remote payload grants substantially more local privilege than is required merely to query the Ipregistry service.Although the URLs use HTTPS and refer to the declared OOMOL vendor domain, HTTPS alone does not protect against compromise of the hosting account, web server, DNS or certificate infrastructure, release pipeline, or vendor publishing credentials. If any of these are compromised, the remote script can be replaced without modifying the reviewed Skill.
The PowerShell form,
irm ... | iex, has the same security properties as the shell form: remotely supplied text is evaluated directly as executable code without an integrity check or an opportunity for inspection.Attack Path
- An attacker compromises the installation-script host, its deployment pipeline, publishing credentials, or another component capable ...[truncated 1723 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-interpreter installation commands from the Skill instructions.
- Direct users to an authenticated package manager or a version-pinned release artifact from the vendor's official release channel.
- Require the artifact to be downloaded to disk rather than executed directly:
- Select an explicit, immutable version.
- Download the installer and its independently published checksum or signature.
- Verify a strong cryptographic checksum or vendor signature before execution.
- Abort installation if verification fails.
- Publish signing keys through a separate trusted channel and document fingerprint verification and key-rotation procedures.
- Require explicit user approval before installing software or executing any downloaded installer. Do not let an agent initiate installation merely because a command is missing.
- Run installation with ordinary user privileges whenever possible. Avoid administrator or root execution unless a clearly documented installation step strictly requires it.
- Prefer platform-native, signed packages with pinned versions and reproducible release metadata.
- Document the files, directories, network endpoints, and privileges used by the CLI so users can evaluate the installation's scope.
