T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:70- Finding
Unverified Remote Installer Execution Through System Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70–77
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The setup instructions download mutable scripts from an external server and immediately execute them using
bashor PowerShell'sInvoke-Expression. Neither command pins a release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded content before execution.Consequently, the code that is actually executed can change after the Skill has been reviewed. Compromise of the distribution server, its deployment process, DNS or another relevant delivery component could turn an otherwise legitimate installation command into arbitrary local code execution.
This behavior also exceeds the Skill's declared operational restriction of
Bash(oo *). Normal functionality only requires invoking an already installedooclient, while these instructions give remotely supplied code access to a general-purpose system shell. The fact that installation is presented only as a fallback reduces invocation frequency but does not remove the execution risk.The documented connector operations necessarily send user-supplied Ragie requests to the declared OOMOL/Ragie service. The reviewed file does not establish covert credential theft or transmission to an unrelated destination; therefore, no separate sensitive-data exfiltration vulnerability is confirmed from the available evidence.
Attack Path
- The agent attempts a documented Ragie operation and receives an `o ...[truncated 1535 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation patterns.
- Direct users to a versioned release artifact from the vendor's official release repository.
- Pin an explicit CLI version rather than downloading a mutable latest installer.
- Download the artifact to a local file without executing it.
- Verify a vendor-provided cryptographic signature or a SHA-256 checksum obtained through a trusted, independently authenticated channel.
- Display the artifact source, pinned version, expected digest, installation effect, and destination before proceeding.
- Require explicit user approval before executing any installation step.
- Install with ordinary user privileges unless elevated privileges are strictly necessary and separately approved.
- Apply equivalent controls to the Windows workflow; do not use
Invoke-Expressionon a network response. - Prefer a documented package-manager installation where package signatures and repository trust are enforced.
- Keep installation outside the Skill's normal execution flow where possible, preserving the declared
Bash(oo *)least-privilege boundary.
