T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 57–61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions pipe scripts retrieved from mutable external URLs directly into a local command interpreter. Neither command pins a specific installer version nor verifies a cryptographic signature or published checksum before execution.
Consequently, the code reviewed in this Skill does not define the code that will ultimately run. The effective payload may change at any time after the Skill has been audited. Although the URLs appear to belong to the declared OOMOL service, domain ownership alone does not establish the integrity of every future response. Compromise of the hosting infrastructure, release pipeline, DNS resolution, or applicable TLS trust chain could substitute arbitrary commands.
Direct remote execution is not necessary for the Skill's declared SerpApi search functionality. Installing a required CLI can be legitimate, but doing so through an unverified pipe-to-shell mechanism grants the installer broader local execution privileges than are required merely to submit search requests.
No evidence in the audited file confirms that the current remote installers are malicious. The vulnerability is the absence of a stable, independently verifiable trust boundary before execution.
Attack Path
- The
oocommand is unavailable, causing the documented first-time setup condition to apply. - A user or agent follows the installation instructions in
SKILL.md. - An attacker compromises or gains control over the installer endpoint, its deployment pipeline, or another relevant delivery dependency.
- The endpoint returns a modif ...[truncated 1104 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both direct execution patterns:
- Do not pipe
curloutput intobash. - Do not pipe
Invoke-RestMethodoutput intoInvoke-Expression.
- Do not pipe
- Prefer an official, version-pinned package distributed through a trusted package manager with integrity and provenance controls.
- If a standalone installer is unavoidable:
- Download it to a local file without executing it.
- Pin a specific release version and immutable release URL.
- Publish its expected SHA-256 or stronger digest through an independently protected channel.
- Verify the digest before execution and abort on any mismatch.
- Prefer cryptographic signature verification using a pinned, documented signing key.
- Allow the user to inspect and explicitly approve the downloaded script.
- Run installation with ordinary user privileges unless a narrowly defined operation explicitly requires elevation. Do not recommend running the entire installer as root or Administrator.
- Document the files, commands, network destinations, and configuration changes performed by the installer.
- In automated agent workflows, stop and request explicit user approval before downloading or executing installation code.
- Pin the CLI version used by the Skill and establish a controlled upgrade process so later installer changes require separate review.
- Remove both direct execution patterns:
