T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:64- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64–68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from
cli.oomol.comand execute the responses immediately usingbashor PowerShellInvoke-Expression. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded content before execution.Although the download host is associated with the declared OOMOL service, remote code can change after the Skill has been reviewed. Compromise of the hosting infrastructure, publishing process, DNS resolution, TLS endpoint, or another part of the upstream supply chain could therefore turn these installation commands into arbitrary code-execution channels.
Installing the required CLI may be necessary for the Skill's functionality, but piping an unverified network response directly into a shell exceeds the minimum privileges and risk required to perform that installation.
Attack Path
- A Mem0 action fails because the
ooCLI is not installed. - The user or Agent follows the first-time setup instructions in
SKILL.md. curlorirmretrieves the current installer from the remote server.- The response is passed directly to
bashoriexwithout integrity or authenticity verification. - If the remote script or delivery path has been compromised, attacker-controlled commands execute with the privileges of the invoking account.
- The payload can access data available to that account, modify local files and configuration, install additional software, or attempt persistence and credential theft.
Impact Assessment
...[truncated 863 chars]
- A Mem0 action fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands from the Skill instructions.
- Prefer a trusted operating-system package manager or a reviewed, version-pinned release package.
- If direct download is unavoidable, separate download from execution so the artifact can be inspected:
- Download to a newly created, non-privileged temporary location.
- Pin an explicit release version rather than using a mutable generic installer URL.
- Validate a publisher signature and a SHA-256 or stronger digest obtained through an independently authenticated channel.
- Reject the artifact if any verification step fails.
- Execute only the verified local artifact.
- Publish installer checksums and signing-key verification instructions in the installation guide.
- Avoid requesting administrator privileges unless a documented installation step strictly requires them.
- Keep installation as a user-initiated prerequisite rather than allowing an Agent to execute an installer automatically after a command failure.
- For PowerShell, avoid
Invoke-Expression; save and verify the signed script before invoking it with an appropriately restricted execution policy.
