T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:67- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 67–71
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from an external server and immediately execute them through Bash or PowerShell. Neither command pins a reviewed release, verifies a cryptographic checksum or signature, nor gives the user an opportunity to inspect the downloaded script before execution.
The effective installation payload is not included in the audited project. Consequently, its behavior can change after this Skill has been reviewed. A compromise of the installer host, publishing infrastructure, DNS or TLS trust chain, or an authorized upstream account could convert these setup commands into an arbitrary-code-execution channel.
Installation is only conditionally suggested when
oois unavailable, which reduces routine exposure. Nevertheless, automatically executing remote code exceeds the minimum privileges needed for the Skill's declared read-only Linux DO operations. The safer prerequisite model is to require a separately installed and verified CLI.Attack Path
- The agent attempts to perform a Linux DO action and receives an
oo: command not founderror. - The Skill directs the agent or user to run one of the first-time installation commands.
- The command retrieves the current installer from
cli.oomol.com. - If the remote installer or its delivery infrastructure has been compromised, attacker-controlled content is returned.
- The shell executes that content immediately without integrity or authenticity verification.
- The payload can perform arbitrary actions available to the account that launched Bash or ...[truncated 731 chars]
- The agent attempts to perform a Linux DO action and receives an
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandirm | iexinstallation instructions. - Treat the
ooCLI as an explicit prerequisite and direct users to a documented, official release page. - Pin the installation instructions to a specific reviewed CLI version rather than a mutable installer URL.
- Download the installation artifact to disk without executing it:
- Use strict HTTPS certificate validation.
- Use a predictable destination that cannot be replaced through an unsafe temporary-file race.
- Do not automatically grant executable permissions or launch the artifact.
- Publish and verify a cryptographic checksum and, preferably, a signature whose verification key is distributed through a separate trusted channel.
- Display the artifact, version, source, expected checksum, and planned installation effects to the user.
- Require explicit user approval before executing any installer.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation. Prompt separately for every privileged operation.
- Prefer a trusted package manager or signed platform-specific package that supports version pinning and provenance verification.
- Fail safely when verification is unavailable or unsuccessful; do not fall back to executing an unverified script.
- Remove all
