T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:72- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 72–76
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions pipe network responses directly into Bash or PowerShell. The downloaded scripts are not pinned to an immutable release, inspected before execution, or validated using a repository-pinned checksum or cryptographic signature.
Although the scripts are served over HTTPS from a vendor-branded domain, HTTPS only protects transport to the endpoint currently controlling that domain. It does not guarantee that the installer remains unchanged after the Skill has been reviewed. Compromise of the hosting infrastructure, vendor account, DNS configuration, TLS termination environment, or installer publishing process could therefore turn these commands into an arbitrary-code execution channel.
This behavior is not necessary for the Skill's core Neon connector operations because those operations only require an already installed
ooCLI. Installation also exceeds the privileges needed merely to document the connector or report that its prerequisite is absent.Attack Path
- An attacker compromises or gains control over
cli.oomol.com, its installer publishing process, or another component capable of changing an installer response. - The attacker replaces
install.shorinstall.ps1with a malicious payload. - The
oocommand is unavailable, causing the Skill's first-time setup instructions to be used. - The agent or user runs the documented command.
curlorirmretrieves the attacker's current response.- Bash or PowerShell executes that response immediately without integrity verification or an inspection boundary.
- The payload operates with the permissi ...[truncated 831 chars]
- An attacker compromises or gains control over
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands.
- Direct users to a documented release page or trusted platform package manager instead of automatically executing a network response.
- Pin the CLI to a specific reviewed version rather than retrieving a mutable latest installer.
- Download the installation artifact to a local file without executing it immediately.
- Verify the artifact using a SHA-256 digest stored in a trusted, version-controlled location or a cryptographic signature whose public key is distributed independently.
- Execute the artifact only after successful verification and explicit user approval.
- Avoid requesting administrator privileges unless a specific installation step demonstrably requires them.
- Keep CLI installation outside the Skill's normal action flow. When the prerequisite is absent, report the condition and provide safe manual installation guidance rather than executing an installer automatically.
- For PowerShell, avoid
Invoke-Expression; use a signed, versioned package and enforce signature validation. - For macOS and Linux, prefer a signed package or pinned package-manager formula with provenance and integrity controls.
