T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 59–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalThe first-time setup instructions provide two platform-specific commands that retrieve mutable scripts from an external server and immediately execute them:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
Both commands pass network responses directly to a command interpreter. The downloaded payload is not pinned to a version and is not validated using a cryptographic signature or expected digest. Users and agents therefore execute whatever content the remote endpoint returns at invocation time, even if that content differs from what existed when the Skill was audited.
The domain is associated with the declared CLI vendor, but domain affiliation does not establish payload integrity. Compromise of the vendor's publishing infrastructure, domain, CDN, DNS resolution, TLS termination, or installer endpoint could replace the expected installer with arbitrary commands.
Installing the CLI is not necessary for normal OpenAlex operations when it is already present. The instructions condition installation on a
command not founderror, which limits exposure, but executing an unverified remote installer still exceeds the minimum privileges required for ordinary OpenAlex read operations.The Windows command has the same underlying issue as the flagged
curl | bashcommand:Invoke-RestMethodobtains mutable content andInvoke-Expressionimmediately interprets it as PowerShell code.The Skill also sends OpenAlex queries, identifiers, filters, and JSON payloads through the disclosed OOMOL connector. That network processing is consistent with the declared connector-based functionality, and the audited file does not instruct the agen ...[truncated 1510 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove instructions that pipe network responses directly into Bash or
Invoke-Expression. - Prefer a trusted operating-system package manager or an officially signed, version-pinned release package.
- If a standalone installer is unavoidable:
- Pin the download to a specific immutable release.
- Download it to a local file instead of executing it directly.
- Publish an expected SHA-256 or stronger digest through an independent trusted channel.
- Verify the digest and, preferably, a vendor signature before execution.
- Allow the user to inspect the downloaded file.
- Execute it only after explicit user approval.
- Document the installer's required permissions and instruct users to run it without administrative privileges unless a specific operation demonstrably requires elevation.
- Do not let an agent install the CLI automatically after an error. Return clear installation guidance and require the user to perform or explicitly approve the installation.
- Consider replacing the commands with links to a versioned installation guide that explains integrity verification and supported package-manager installation methods.
- Remove instructions that pipe network responses directly into Bash or
