T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:66- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 66–70
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable content from
cli.oomol.comand immediately execute it using Bash or PowerShell. The instructions do not pin a release version, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded script before execution.HTTPS protects the script while it is in transit, but it does not guarantee that the server will always return the same audited payload. Compromise of the hosting account, publishing pipeline, domain, or server could therefore turn these installation commands into arbitrary code-execution channels. This behavior also prevents the effective installation payload from being fully evaluated as part of the static Skill audit.
Although installing the declared
ooCLI is relevant to the Skill's functionality and the instructions only recommend installation after a command-not-found error, direct pipe-to-shell execution exceeds the minimum privilege and integrity requirements necessary to install that tool safely.Attack Path
- The user requests a Quo operation and the
oocommand is unavailable. - The Skill follows its documented first-time setup fallback.
- The Agent or user executes the applicable Bash or PowerShell installation command.
- The command retrieves the current script from
cli.oomol.comwithout validating its version, checksum, or publisher signature. - If the remote host or its release pipeline supplies a modified script, the shell executes the attacker's instructions immediately.
- The payload runs with the privileges of the invo ...[truncated 1029 chars]
- The user requests a Quo operation and the
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-shell installation commands.
- Link to a documented official installation procedure using versioned release artifacts.
- Pin the CLI to an explicitly reviewed version rather than downloading a mutable latest installer.
- Download the installer or binary to a local file without executing it immediately.
- Publish and verify a cryptographic signature from a trusted release key, or at minimum verify a pinned SHA-256 digest obtained through an independently protected channel.
- Abort installation if verification fails; do not silently fall back to execution.
- Prefer signed, platform-native packages with clear publisher identity where available.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Document the files, network endpoints, and permissions used by the installer so users can assess its effects.
- Apply equivalent integrity and version-pinning controls to both the Bash and PowerShell installation paths.
