T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installer Scripts Executed Directly by Shell Interpreters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
Both installation commands retrieve scripts from
cli.oomol.comand immediately execute the received content with Bash or PowerShell. The instructions do not pin a release, verify a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded script before execution.Consequently, the effective code executed by the Skill can change after the package has been audited. HTTPS protects the connection in transit but does not mitigate compromise of the distribution server, DNS or certificate infrastructure, publishing account, or installer build pipeline. The PowerShell command has the same security properties as the
curl | bashpattern becauseInvoke-Expressionevaluates the retrieved response as code.Installing the required CLI may support the declared RenderForm integration, but immediate execution of mutable remote content exceeds the minimum mechanism necessary to perform that installation.
Attack Path
- An attempted
oocommand fails because the CLI is unavailable. - The Skill directs the user or Agent to run one of the first-time installation commands.
- The command contacts
cli.oomol.comand retrieves the current installer without version or integrity verification. - If the hosting service, publishing pipeline, domain, or installer content has been compromised, an attacker returns a modified script.
- Bash or PowerShell immediately executes the attacker-controlled response with the privileges of the invoking user.
- The payload can access resources available to that account and may install additio ...[truncated 889 chars]
- An attempted
- Remediation
View remediation
Remediation Suggestions
- Remove both direct download-to-interpreter pipelines.
- Distribute the CLI through a trusted package manager or provide a pinned release artifact from an immutable release URL.
- Download the installer or binary to disk without executing it automatically.
- Publish and verify a cryptographic checksum or signature using a trusted, separately distributed verification key.
- Fail closed if integrity or signature verification fails.
- Allow the user to inspect the resolved artifact and require explicit approval before execution.
- Run installation with ordinary user privileges unless a specific installation step demonstrably requires elevation.
- Document the files, directories, and configuration that the installer will modify.
- Where possible, avoid installation entirely by requiring the user to install the CLI independently before enabling the Skill.
