T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Shell Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The setup command downloads a mutable shell script from an external server and pipes it directly into
bash. It provides no version pinning, cryptographic signature verification, checksum validation, or opportunity to inspect the downloaded artifact before execution.HTTPS protects the connection in transit, but it does not establish that the current script is the same artifact that was reviewed. Compromise of the hosting service, publishing account, DNS infrastructure, or installer pipeline could cause arbitrary attacker-controlled commands to execute. This installation behavior also exceeds the routine
Bash(oo *)tool boundary declared by the Skill because it requires a general-purpose shell to execute externally supplied code.Attack Path
- The
oocommand is absent, causing the documented first-time setup fallback to be used. - An attacker compromises or gains control over the installer endpoint or its release pipeline.
- The endpoint serves a modified
install.shpayload. curlsends the response directly tobashwithout validation or review.- The payload executes with the privileges of the user running the setup command.
- The payload can access that user's files and credentials, modify local tools, install persistence mechanisms, or transmit data to attacker-controlled infrastructure.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's account. The accessible scope includes files, environment data, credentials, network resources, and applications available to that user. If the command is run from a privileged shell, the impact can extend to system-wide m ...[truncated 215 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Do not pipe downloaded content directly into a shell.
- Distribute the CLI through a trusted package manager or a version-pinned official release.
- Download the installer or binary to a local file as a separate step.
- Verify a vendor-provided cryptographic signature or a SHA-256 checksum obtained through an independently authenticated channel.
- Pin the expected installer or release version so its effective contents cannot change silently after review.
- Permit inspection of the downloaded file before execution.
- Run installation with the least-privileged account possible and avoid requesting elevated privileges unless a documented operation strictly requires them.
- Document the files, permissions, and network endpoints used by the installer.
