T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup instructions pipe content retrieved from an external server directly into
bashor PowerShell'sInvoke-Expression. The downloaded installers are executed without:- Pinning an immutable version or release artifact.
- Verifying a cryptographic signature or checksum.
- Saving and reviewing the installer before execution.
- Constraining its filesystem, network, or process privileges.
- Requiring explicit user approval immediately before execution.
HTTPS protects data in transit but does not establish that the retrieved script is safe. The effective payload can change after the Skill has been reviewed. Compromise of the vendor server, CDN, DNS infrastructure, publishing credentials, or installer pipeline could therefore turn these documented setup commands into arbitrary code execution.
Installing the required CLI is relevant to the Skill's operation, and the instructions only recommend installation after a command-not-found failure. However, immediate execution of mutable remote content exceeds the minimum privileges and assurance necessary to install the dependency safely.
Attack Path
- A SecurityTrails action is requested on a system where the
ooCLI is unavailable. - The initial
oocommand fails withoo: command not found. - The user or agent follows the first-time setup instructions in
SKILL.md. - The command retrieves the current installer response from
cli.oomol.com. - A compromised server or software-distribution pipeline supplies an attacker-controlled script.
- The shell executes that response immediately, without integrity verification ...[truncated 1007 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace pipe-to-shell and
Invoke-Expressioninstallation with a pinned package-manager release or immutable release artifact. - Pin an explicit
ooCLI version rather than retrieving a mutable installer endpoint. - Download the installer or binary to a local file without executing it automatically.
- Publish a cryptographic signature and SHA-256 checksum through a separately protected channel.
- Verify the signature and pinned checksum before any execution or installation step.
- Require explicit user approval before installing software or running a downloaded installer.
- Show the exact artifact URL, version, expected signer, checksum, destination paths, and requested permissions.
- Execute installation with ordinary user privileges unless a specific operation demonstrably requires elevation.
- Document all filesystem, environment, shell-profile, and network changes performed by the installer.
- Prefer platform-native package managers that support signed metadata and version pinning.
- Replace pipe-to-shell and
