T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Scripts Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 59–63
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand immediately execute the returned content using Bash or PowerShell. The commands do not pin a release, verify a cryptographic checksum or signature, or provide an opportunity to inspect the downloaded scripts before execution.Although installing the
ooCLI supports the Skill's declared Serpdog connector functionality, direct remote-to-shell execution is not the minimum privilege necessary to accomplish that installation. HTTPS protects the connection in transit but does not establish that the current server response is the same code reviewed with this Skill. A compromised origin, hosting account, CDN, DNS/control plane, or future installer revision could replace the effective payload after the Skill package has been audited.The instructions limit installation to a fallback after an
oo: command not founderror, which reduces invocation frequency but does not mitigate the integrity risk when the fallback is used.Attack Path
- The agent attempts to invoke the
ooCLI for a Serpdog request. - The command fails because the CLI is unavailable.
- Following the documented fallback, the agent runs the applicable installation command.
- Bash or PowerShell retrieves the current response from
cli.oomol.com. - The shell executes that response immediately without local verification.
- If the remote distribution channel or installer has been compromised or maliciously changed, attacker-controlled commands execute with the privileges of the user or agent process.
Impac
...[truncated 642 chars]
- The agent attempts to invoke the
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation patterns. - Pin the installer or binary to a specific, reviewed CLI release rather than retrieving a mutable latest-version script.
- Download the artifact to a local file without executing it.
- Verify the artifact against a checksum published through an independent trusted channel. Prefer a cryptographic release signature with a pinned and authenticated signing key.
- Display the selected version, source, verification result, and intended installation changes before requesting explicit user approval.
- Execute the verified installer as a separate step with ordinary user privileges. Do not request administrative privileges unless a specific installation operation requires them.
- Prefer a trusted platform package manager or signed release package where available.
- Keep CLI installation outside automatic Skill execution where possible and instruct the user to complete installation manually.
- If script-based installation must remain supported, publish immutable versioned URLs and fail closed when integrity verification cannot be completed.
- Remove the
