T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installers Are Downloaded and Executed Directly
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The installation instructions retrieve mutable scripts from `cli.oomol.com` and immediately execute them with Bash or PowerShell. The scripts are not included in the audited project, so their effective behavior cannot be reviewed from the repository and may change after this audit. Although installing the `oo` CLI is relevant when the required tool is absent, direct `curl | bash` and `irm | iex` execution is not the minimum safe installation mechanism. The instructions do not pin a release, validate a cryptographic signature or checksum, present the downloaded content for inspection, or require explicit approval immediately before execution. Using HTTPS protects data in transit under ordinary conditions, but it does not protect against compromise of the hosting service, release pipeline, account, or trusted endpoint. There is no evidence in the reviewed file that the current remote scripts are malicious; the vulnerability is that their future content is implicitly trusted and executed. ### Attack Path 1. The `oo` command is unavailable on the user's system. 2. The Agent or user follows the documented first-time setup instructions. 3. Bash or PowerShell downloads the current installer from `cli.oomol.com`. 4. The shell executes the response without first saving, inspecting, pinning, or cryptographically verifying it. 5. If the remote endpoint or its software-distribution pipeline has been compromised, attacker-controlled commands execute wit ...[truncated 1022 chars]- Remediation
View remediation
/install.sh" echo " oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.sh ``` The production instructions should use the vendor's actual immutable release URL and independently published signature or checksum. ]]>
