T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:65- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Loyverse connector skill is mostly coherent, but its setup instructions tell the agent or user to execute a remotely downloaded installer script without verification.
Install only if you are comfortable using OOMOL as an intermediary for Loyverse data and handling the oo CLI setup yourself. Avoid running the pipe-to-shell installer commands as written; prefer an official, verifiable installation method and confirm any account connection or billing step before proceeding.
SKILL.md:65Unverified Remote Installer Downloaded and Executed Directly
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This creates a supply-chain and remote code execution risk because any compromise of the hosting endpoint, TLS interception in a hostile environment, or unexpected script change would execute arbitrary code on the user's system without review.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
No suspicious patterns detected.