T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions pipe a remotely hosted installation script directly into Bash. The command does not pin a reviewed release, validate a cryptographic checksum, or verify a publisher signature before execution. Consequently, the code that ultimately runs can change after the Skill has been reviewed.
HTTPS provides transport protection but does not establish the long-term integrity of the installer. If the hosting account, server, DNS resolution, certificate issuance path, or release pipeline is compromised, the downloaded script could contain attacker-controlled commands. The fallback-only placement reduces how often the command is used but does not eliminate the vulnerability.
This behavior exceeds the minimum privileges required for the declared read-only lemlist functionality. Reading lemlist data requires an installed connector client and network access, whereas running the installer permits unspecified remote code to act with all privileges available to the invoking user.
Attack Path
- The
ooCLI is absent, causing anoo: command not founderror. - The user or Agent follows the documented first-time setup fallback.
- The command downloads the current contents of
https://cli.oomol.com/install.sh. - The downloaded content is passed directly to Bash without prior inspection or integrity verification.
- If the distribution endpoint or pipeline is compromised, attacker-controlled shell commands execute under the invoking user's account.
Impact Assessment
A malicious installer could read or modify any data accessible to the invoking user, including local application data and credentials; alter shell configuration; ...[truncated 314 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation pattern. - Direct users to a version-pinned release artifact from an authenticated release page.
- Download the artifact to a local file without executing it immediately.
- Publish and verify a SHA-256 digest or, preferably, a cryptographic publisher signature before installation.
- Allow the user to inspect the installer before execution.
- Require explicit user approval before installing software.
- Run installation with ordinary user privileges unless a narrowly scoped privileged operation is demonstrably required.
- Document the exact files, permissions, and network endpoints used by the installer.
- Remove the
