T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:61-70
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalThe first-time setup instructions provide remote-to-interpreter installation commands for both macOS/Linux and Windows:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
These commands retrieve mutable content from
cli.oomol.comand immediately execute it with the current user's privileges. They do not pin a version, verify a cryptographic checksum or signature, save the script for inspection, or otherwise establish that the downloaded bytes match an audited release.Although the hostname is associated with the Skill's declared OOMOL service and the instructions are only a fallback when
oois unavailable, direct download-to-interpreter execution is not necessary to provide Productlane connector functionality. The effective code executed can change after the Skill itself has been reviewed. Compromise of the hosting service, publishing pipeline, domain, DNS resolution, TLS trust chain, or installer content could therefore turn the documented setup process into arbitrary local code execution.Attack Path
- The user or Agent attempts to use the Skill on a system where the
ooCLI is unavailable. - It follows the documented first-time setup procedure.
curlor PowerShell downloads a mutable installer response fromcli.oomol.com.- The response is passed directly to Bash or PowerShell without integrity verification or review.
- If the remote content or its delivery path has been compromised, attacker-controlled commands execute with the invoking user's privileges.
- Those commands can access data and resources available to that account and may install further components.
Impact Assessment
Successful ...[truncated 596 chars]
- The user or Agent attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Replace the pipe-to-shell and
Invoke-Expressioninstructions with a trusted package-manager installation or a signed release artifact. - Pin the CLI to a specific immutable version rather than retrieving the latest mutable installer.
- Publish a cryptographic checksum and preferably a signature backed by a documented release key.
- Download the installer or binary to a local file, verify its signature and checksum, and only then execute it.
- Display the exact artifact source, version, expected digest, and verification commands in
SKILL.md. - Run installation with the least-privileged account possible and avoid requesting administrator or root privileges unless strictly required.
- Apply equivalent verification controls to both the Bash and PowerShell installation paths.
- Keep installation separate from normal Skill execution; do not allow an Agent to install software automatically without explicit user approval.
- Replace the pipe-to-shell and
