T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installation Scripts Are Downloaded and Executed Directly
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The setup instructions pipe remotely downloaded scripts directly into Bash or PowerShell. The remote content is executed immediately without being saved for inspection, pinned to a reviewed version, or verified using a cryptographic signature or checksum. Although `cli.oomol.com` is consistent with the service named by the Skill, the scripts are mutable external resources. Compromise of the hosting service, DNS infrastructure, TLS termination, deployment pipeline, or vendor account could change the effective payload after the Skill has been reviewed. The Skill would then direct execution of attacker-controlled commands. Installing software is not required for normal Lob address-verification operations when the `oo` CLI is already present. Consequently, automatic or agent-directed execution of an unverified installer exceeds the minimum privileges necessary for the Skill's ordinary functionality. ### Attack Path 1. The `oo` command is absent or made unavailable in the execution environment. 2. An agent or user follows the documented first-time setup instructions. 3. `curl` or `irm` retrieves the current installer from `cli.oomol.com`. 4. The response is passed directly to Bash or `Invoke-Expression` without integrity verification or inspection. 5. If the remote delivery infrastructure or installer has been compromised, arbitrary attacker-supplied commands execute with the privileges of the invoking user. 6. Those commands can access the ...[truncated 972 chars]- Remediation
View remediation
