T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions retrieve mutable scripts from an external URL and execute them immediately through Bash or PowerShell. Neither command pins a script or CLI version, verifies a cryptographic signature or checksum, nor saves the payload for inspection before execution.
HTTPS protects the connection in transit but does not establish payload immutability or protect users if the hosting server, publishing account, domain, or release process is compromised. The effective code can therefore change after the Skill has been reviewed. The PowerShell
Invoke-Expressionpattern has the same security properties as piping the response into Bash.Installing the CLI may be necessary when
oois unavailable, but immediate execution of unverified network content exceeds the minimum mechanism needed to provide installation guidance.Attack Path
- The
oocommand is absent, causing the user or agent to follow the first-time setup instructions. - An attacker compromises or gains control over the remote script endpoint, its publishing pipeline, or associated infrastructure.
- The attacker replaces the installation response with arbitrary shell commands.
curl ... | bashorirm ... | iexexecutes the current response without integrity validation or prior review.- The payload operates with the privileges of the invoking shell and can access resources available to that user.
Impact
...[truncated 632 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace direct pipe-to-shell and
Invoke-Expressioninstructions with installation through a reputable platform package manager or a pinned release artifact. - Pin an explicit CLI version rather than downloading a mutable installer from a generic endpoint.
- Download the artifact to disk without executing it, then verify a vendor-published cryptographic signature or strong checksum obtained through an independently authenticated channel.
- Allow the user to inspect the downloaded script and require explicit approval before execution.
- Document the permissions required by the installer and advise users to run it without elevated privileges unless a specific, justified step requires elevation.
- Publish reproducible release artifacts and retain versioned checksums or signatures so reviewed installation content cannot be changed silently.
- For PowerShell, avoid
Invoke-Expression; use a signed, versioned package or save and validate the installer before launching it with a constrained execution policy.
- Replace direct pipe-to-shell and
