T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:52- Finding
Unverified Remote Shell Script Execution
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ``` ### Technical Analysis The installation command downloads a mutable shell script from an external URL and immediately pipes it into Bash. The Skill does not pin the script to a version or cryptographic digest, verify a digital signature, or provide an opportunity to inspect the downloaded content before execution. HTTPS protects the connection in transit but does not ensure that the hosted script remains identical to the version available when the Skill was audited. Compromise of the OOMOL domain, hosting infrastructure, release process, or administrative credentials could therefore replace the installer with arbitrary commands. Installing a required CLI can be consistent with the Skill's function, but immediate execution of unverified remote content is not the minimum privilege or safest installation mechanism necessary to achieve that purpose. ### Attack Path 1. The `oo` command is unavailable on the user's system. 2. The setup instructions direct the user or agent to run the documented installation command. 3. `curl` retrieves the current contents of `https://cli.oomol.com/install.sh`. 4. The response is sent directly to Bash without integrity or authenticity verification. 5. A compromised or malicious response executes arbitrary shell commands with the privileges of the invoking account. ### Impact Assessment Successful exploitation permits arbitrary code execution under the invoking user's privileges. Potential effects include reading or modifying files accessible to that account, stealing locally available credentials, installing additional software, alte ...[truncated 317 chars]- Remediation
View remediation
