T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Shell Script Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command downloads a mutable remote script and pipes it directly into Bash. The script is executed without pinning a release version, verifying a cryptographic signature or checksum, or giving the user an opportunity to inspect the downloaded content.
HTTPS protects the connection in transit but does not independently establish the integrity or trustworthiness of the script served by the remote host. If the hosting infrastructure, DNS, certificate issuance, publishing account, or installer itself is compromised, the server can supply arbitrary shell commands. Because the effective payload is retrieved at execution time, it can also differ from the payload available when this Skill was audited.
Installing the required CLI is related to the Skill's functionality, but immediate execution of unverified network content exceeds the minimum risk necessary to perform that installation. A pinned and cryptographically verified release artifact would provide the same functionality with a smaller trust boundary.
Attack Path
- The
ooCLI is unavailable and an agent or user follows the first-time setup instructions. - The command connects to
cli.oomol.comand retrieves the current contents ofinstall.sh. - A compromised publishing pipeline, hosting service, DNS path, certificate authority, or vendor account supplies a modified installer.
- Bash executes the response immediately, before the user can inspect or validate it.
- The modified installer runs arbitrary commands with the privileges of the user who invoked the installation command.
- Those commands can access local data, credentials, environment variables, and netwo ...[truncated 763 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation command. - Direct users to a version-pinned release artifact or trusted platform package manager.
- Download the installer or binary to a local file without executing it automatically.
- Publish an expected SHA-256 or stronger digest through a separately controlled channel and require verification before execution.
- Prefer cryptographically signed release artifacts and verify the signature against a documented, pinned publisher key.
- Require explicit user approval before executing an installer or granting elevated privileges.
- Run installation with the least-privileged account possible and document any filesystem or network permissions it requires.
- If a script remains necessary, use a safer sequence such as download, integrity verification, inspection, and then explicit execution.
- Remove the direct
