T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Executed Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a mutable shell script from
https://cli.oomol.com/install.shand pipes it directly into Bash. The command does not pin a release, verify a cryptographic signature or checksum, or provide an opportunity to inspect the downloaded script before execution.Consequently, the effective code executed on the host can change after the Skill has been audited. Compromise of the remote service, its DNS or TLS infrastructure, or its release process could turn this installation path into an arbitrary-code-execution channel. Although the instruction is presented as a conditional first-time setup step, executing remote code in this manner exceeds the minimum privileges required merely to document or use the connector.
Attack Path
- The
ooCLI is absent, causing the documented first-time setup condition to apply. - The user or Agent runs the provided installation command.
curlretrieves the current contents of the mutable remote installer.- The response is passed directly to Bash without integrity or authenticity verification beyond transport-layer TLS.
- A compromised or malicious response executes with the privileges of the invoking user.
- The payload can read or modify accessible files, steal session credentials, run additional commands, install persistence, or download further payloads.
Impact Assessment
Successful exploitation provides arbitrary command execution with the permissions of the account running Bash. The accessible scope may include user files, environment variables, authentication material, local application data, and any resources available through the user's active s ...[truncated 266 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation pattern. - Direct users to a version-pinned release hosted in a verifiable official repository or package manager.
- Download the installer as a separate file without executing it automatically.
- Publish and require verification of a cryptographic signature or a checksum obtained through an independently trusted channel.
- Allow the installer to be inspected before execution.
- Require explicit user approval before installing software or running any downloaded installer.
- Run installation with the least-privileged account possible and avoid requesting elevated privileges unless a documented component strictly requires them.
- Prefer an auditable sequence such as download, signature verification, review, and explicit execution.
- Remove the
