T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Shell Script Execution via curl and Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction streams a mutable remote response directly into Bash. No fixed release version, cryptographic checksum, digital signature, or manual review step is used before execution. HTTPS authenticates and encrypts the connection under normal conditions, but it does not ensure that the remote server will always return the same reviewed installer.
If the vendor host, publishing account, CDN, DNS resolution, or installer release process is compromised, the response can contain arbitrary shell commands. Those commands execute immediately with the privileges of the user running the installation.
The Skill's declared OpenSea functionality only requires invoking an installed
ooCLI for API queries. Arbitrary remote shell execution is therefore not the minimum privilege necessary to perform the declared read operations.Attack Path
- A user or agent attempts an OpenSea action and receives an
oo: command not founderror. - The user or agent follows the documented first-time installation instruction.
- An attacker compromises or gains control over the installer delivery path or upstream publishing infrastructure.
curlretrieves the attacker-controlled response from the expected URL.- The shell pipeline passes that response directly to Bash without verification.
- Bash executes the payload with the invoking user's permissions.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking account. The payload could read accessible files and credentials, modify project or user files, install additional software, alter shell configuration, or establish persistence where the acc ...[truncated 166 chars]
- A user or agent attempts an OpenSea action and receives an
- Remediation
View remediation
Remediation Suggestions
Remove the pipe-to-shell installation pattern. Use a hardened installation process that:
- Pins the CLI to a specific reviewed release and immutable artifact URL.
- Downloads the artifact to a local file without executing it.
- Verifies a vendor-published cryptographic checksum and, preferably, a digital signature whose trust key is distributed independently.
- Stops installation if verification fails.
- Allows the user to inspect the artifact and explicitly approve execution.
- Executes the installer without elevated privileges unless a documented operation strictly requires them.
- Uses a trusted package manager or signed package repository where available.
The Skill should preferably tell users to install the CLI manually from documented, versioned releases rather than allowing an agent to execute an installer automatically.
