T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:65- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:65-69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from
cli.oomol.comand immediately execute them through Bash or PowerShell. Neither command pins an installer version nor verifies a cryptographic signature or checksum. Users and agents therefore cannot inspect or authenticate the effective payload before execution, and the payload can change after the Skill has been reviewed.HTTPS provides transport protection but does not establish that the downloaded script is safe. Compromise of the hosting server, publishing account, DNS infrastructure, or installer pipeline could cause arbitrary attacker-controlled commands to run. The use of PowerShell
Invoke-Expression(iex) and a directcurl | bashpipeline removes the review boundary between retrieval and execution.Installing a CLI can be necessary for the declared Outlook connector functionality, but immediate execution of unverified remote code exceeds the minimum mechanism required to perform that installation. A verified, version-pinned package or separately downloaded and inspected installer would provide the required functionality with materially lower risk.
Attack Path
- The
ooCLI is unavailable, causing the user or agent to consult the first-time setup instructions. - The user or agent runs the documented command on macOS, Linux, or Windows.
- The command downloads the current script served by
cli.oomol.com. - The downloaded content is passed directly to Bash or PowerShell without integrity verification or inspection.
- If the remote endpoint or its publishing infrastru ...[truncated 1073 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation patterns. - Direct users to an official, version-pinned release artifact or trusted operating-system package repository.
- Publish expected SHA-256 hashes and require verification before execution.
- Cryptographically sign release artifacts and document signature verification against a pinned, independently distributed public key.
- Separate download and execution into distinct steps so the installer can be inspected before it runs.
- Document the installer's required permissions, filesystem changes, network destinations, and rollback procedure.
- Advise users to install without administrative privileges unless a specific, justified operation requires elevation.
- If automated installation remains necessary, pin the exact release URL and fail closed when checksum or signature validation does not succeed.
- Remove the
