T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction pipes a remotely downloaded, mutable shell script directly into Bash. The command does not pin a reviewed release, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded content before execution.
Although the hostname is consistent with the declared OOMOL service, the repository does not contain the script or evidence that its content is immutable and trusted. Consequently, the effective payload can change after this Skill has been reviewed. This behavior exceeds the minimum privileges needed to operate the Placid connector: connector operations require the
ooCLI, but they do not inherently require arbitrary remote code to be executed without verification.Attack Path
- The
oocommand is unavailable, causing the agent or user to consult the first-time setup instructions. - An attacker compromises the installation script, its hosting account, the serving infrastructure, or another relevant supply-chain component.
- The victim runs the documented
curlpipeline. curlretrieves the attacker-controlled script and passes it directly to Bash.- Bash executes the payload with the permissions of the invoking account, without integrity validation or prior inspection.
Impact Assessment
A malicious installation payload could execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the host configuration, it could read or modify accessible files, steal local credentials and tokens, alter development tools, install persistence, or download additional payloads. The reviewed Skill does not itself request elevated privileges, s ...[truncated 142 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Prefer installation through a trusted operating-system package manager or a vendor package repository with signed metadata.
- Pin the CLI to a specific reviewed version rather than downloading a mutable latest installer.
- Download the installer to a local file first, then verify a vendor-provided cryptographic signature and a pinned SHA-256 digest before execution.
- Publish the expected digest through a separate authenticated channel and fail closed if verification does not succeed.
- Require explicit user approval before installing software or executing an installer.
- Run installation with the minimum necessary account privileges and avoid requesting administrative privileges unless strictly required.
- Remove the direct
