T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's Plain integration is mostly coherent, but its fallback setup includes unverified remote installer commands that could execute changing code on the user's machine.
Review this skill before installing. It appears intended for legitimate Plain operations, but avoid letting an agent run the remote installer commands automatically; install the oo CLI through a verified, versioned method when possible, and confirm any customer upsert payload before execution.
SKILL.md:58Unverified Remote Installer Downloaded and Executed Directly
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This is dangerous because it executes unverified code from the network without integrity checking, version pinning, or user review; if the host, transport, or distribution path is compromised, arbitrary code execution follows immediately.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
This manifest description is a trigger/invocation cue in a markdown/manifest file, and it is extremely broad. It lacks scope boundaries or negative examples, so many ordinary tasks that merely mention Plain could unintentionally invoke the skill.
No suspicious patterns detected.