T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:66- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Postmark connector, but its setup and command examples create review-worthy local execution risks.
Review this skill before installing. It appears intended for legitimate Postmark work, but avoid running the documented one-line remote installers unless you independently trust and verify the oo CLI source. For actual Postmark actions, prefer passing JSON via a file and require explicit confirmation before sending emails, batch sends, or template changes.
SKILL.md:66Unverified Remote Installer Download and Immediate Execution
SKILL.md:29Shell Command Injection Risk Through Inline JSON Payload Construction
The skill instructs users to install software by piping a remote script directly into a shell (curl ... | bash). This creates a supply-chain execution risk: if the remote host, CDN, TLS termination, or install script is compromised, arbitrary code will execute immediately on the user's system without integrity verification or an opportunity for review.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Postmark request" and "Whenever a task involves Postmark," which is very broad and could match many ordinary mentions of Postmark without clarifying boundaries or exclusions. The file does not provide negative examples or tighter trigger constraints to distinguish when the skill should or should not activate.
No suspicious patterns detected.