T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Installation Scripts Executed Directly by System Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62–66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup documentation downloads mutable scripts from
cli.oomol.comand immediately passes their contents tobashor PowerShell for execution. There is no pinned script version, expected cryptographic hash, digital-signature validation, or opportunity to inspect the downloaded content before execution.HTTPS protects the connection in transit under normal conditions, but it does not ensure that the server-hosted script remains identical to the version intended when the Skill was reviewed. Compromise of the installation endpoint, its deployment pipeline, the hosting account, or the trusted delivery infrastructure could therefore replace the installer with arbitrary commands.
Installing the
ooCLI is relevant to the declared functionality, but directly executing an unverified network response exceeds the minimum mechanism necessary to perform that installation. A separately downloaded, version-pinned, and cryptographically verified artifact would provide the required functionality with substantially lower risk.No evidence establishes that the currently hosted scripts contain malicious code. The vulnerability arises because the effective code is remote, mutable, and executed without local verification.
Attack Path
- A user or agent attempts to invoke the Skill and receives an
oo: command not founderror. - The agent follows the first-time setup instructions in
SKILL.md. - The shell retrieves the current response from
https://cli.oomol.com/install.shorhttps://cli.oomol.com/install.ps1. - The response is passed directly to
bashoriexwithout v ...[truncated 1200 chars]
- A user or agent attempts to invoke the Skill and receives an
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-shell installation commands.
- Direct users to a version-pinned release artifact or trusted platform package manager rather than a mutable installation endpoint.
- Require the artifact to be downloaded to a local file before execution.
- Publish and verify a cryptographic checksum, such as SHA-256, over the downloaded artifact.
- Prefer digital signatures tied to a documented publisher identity and require signature verification before installation.
- Display or permit inspection of the downloaded installer before it is executed.
- Pin the expected CLI version so future server-side changes cannot silently alter the reviewed payload.
- Document that installation should occur as an unprivileged user unless a specific, narrowly scoped operation demonstrably requires elevation.
- For managed environments, recommend installation through an organization-approved software distribution channel.
- If an installation script remains necessary, fail closed when checksum or signature verification cannot be completed.
