T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:54- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The setup instructions retrieve mutable scripts from external URLs and immediately execute them through Bash or PowerShell. They do not pin an installer version, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded content before execution. The reviewed Skill does not contain the effective installer payload. Consequently, the executed code can change after the Skill has been audited. Compromise of the hosting server, DNS or TLS delivery chain, deployment credentials, or installer publication process could turn these commands into arbitrary code-execution mechanisms. Installing the `oo` CLI is relevant only when the command is absent, but immediate execution of unverified remote content exceeds the minimum privilege and trust required for that setup task. A verified package, signed release artifact, or separately downloaded and inspected installer would provide safer alternatives. The same weakness exists on both supported platform paths: - macOS/Linux: `curl ... | bash` - Windows: `irm ... | iex` ### Attack Path 1. The `oo` command is unavailable, causing the first-time setup fallback to be used. 2. An agent or user follows the documented installation command. 3. The command requests the current installer from `cli.oomol.com`. 4. An attacker who has compromised the installer host, publication pipeline, or relevant delivery infrastructure substitutes malicious script content. 5. Bash or PowerShe ...[truncated 1087 chars]- Remediation
View remediation
/install.sh' echo ' oo-install.sh' | shasum -a 256 --check - less oo-install.sh bash oo-install.sh ``` An equivalent Windows process should download the pinned script to disk, validate its expected hash and publisher signature, present it for review, and execute it only after explicit approval. ]]>
