T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions pipe scripts retrieved from external URLs directly into Bash or PowerShell. The content is executed without pinning an immutable release, verifying a cryptographic digest or publisher signature, or providing an opportunity to inspect the downloaded file.
HTTPS protects the connection in transit but does not establish that the mutable script remains safe after this Skill has been reviewed. Compromise of the distribution server, hosting account, DNS path, signing infrastructure, or upstream build process could cause arbitrary attacker-controlled commands to be returned and immediately executed.
Installing the CLI is conditional on
oobeing unavailable, but remote script execution is not required for ordinary read-only Scopus operations when a trusted CLI installation already exists. The installation method therefore introduces privileges and supply-chain exposure beyond those needed to issue Scopus queries.Attack Path
- A user requests a Scopus operation.
- The
oocommand is unavailable, causing the documented first-time setup path to be followed. - The agent or user runs one of the installation commands.
- The external endpoint, or infrastructure controlling its response, supplies modified script content.
- Bash or PowerShell executes that content immediately under the invoking user's account.
- The payload can perform arbitrary actions available to that account before proceeding with, imitating, or abandoning installation.
Impact Assessment
Successful exploitation grants arbitrary comman ...[truncated 555 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both direct execution patterns:
curl | bashandirm | iex. - Prefer a trusted platform package manager and pin an exact CLI version.
- If direct download is unavoidable, use a version-specific immutable artifact URL.
- Download the artifact to a local file without executing it.
- Verify a pinned SHA-256 digest and a cryptographic signature tied to a documented publisher key.
- Abort installation on any verification failure.
- Allow the script or package contents to be reviewed before execution.
- Run installation without administrative privileges unless a specific installation step demonstrably requires them.
- Keep installation separate from normal Skill execution and require explicit user approval before installing software.
- Document the files, permissions, and system changes made by the installer.
- Remove both direct execution patterns:
