T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand pass their contents directly to Bash or PowerShell. No version is pinned, and neither command verifies a cryptographic signature or checksum before execution. The user also has no mandatory opportunity to inspect the downloaded code.Installing the
ooCLI may be necessary when it is absent, but executing an unverified network response directly in a shell exceeds the minimum safe installation mechanism. The effective installer can change after the Skill has been audited. Although the file identifies this as an OOMOL domain, the audited project contains no evidence establishing the integrity of every future response from that domain.Attack Path
- An attempted connector command fails because the
ooCLI is unavailable. - The user or agent follows the documented first-time setup command.
- The command retrieves the current installer response from
cli.oomol.com. - An attacker who compromises the distribution server, installer publication process, or relevant network/trust infrastructure supplies modified script content.
- Bash or PowerShell executes that content immediately, without integrity verification or prior inspection.
- The payload performs arbitrary actions using the permissions of the account that invoked the installation command.
Impact Assessment
Successful exploitation provides arbitrary code execution with the invoking user's privileges. Depending on those privileges and the attacker's payload, the affected scope can include local file ...[truncated 454 chars]
- An attempted connector command fails because the
- Remediation
View remediation
Remediation Suggestions
- Replace direct
curl | bashandirm | iexexecution with installation through a trusted platform package manager where possible. - Pin the CLI to an explicit release version rather than retrieving a mutable generic installer.
- Download the installer or release artifact to a local file without executing it.
- Publish a cryptographic checksum or signature through an independently protected release channel and verify it before execution.
- Abort installation if signature, checksum, expected publisher, or pinned-version validation fails.
- Allow the user to inspect the downloaded script and require explicit approval before running it.
- Run the installer with ordinary user privileges unless a documented installation step strictly requires elevation.
- Document the files, configuration changes, and network endpoints used by the installer so users can evaluate its scope.
- Replace direct
