T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Executed Directly by Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction downloads a mutable shell script from an external URL and sends it directly to Bash. The remote payload is executed without first saving it for inspection, pinning a specific release, or validating a cryptographic signature or checksum.
Although HTTPS protects the connection in transit, it does not ensure that the script remains unchanged after the Skill has been audited. A compromise of the remote domain, installer publication pipeline, hosting environment, or authorized publisher account could replace the installer with arbitrary shell commands.
Installing the CLI may be relevant to first-time setup, but arbitrary remote shell execution exceeds the minimum privileges required for the Skill's declared read-only ServerAvatar queries. The CLI should instead be a user-managed prerequisite installed through a verifiable, consent-based process.
Attack Path
- The Agent attempts to use the Skill and receives an
oo: command not founderror. - The Agent follows the first-time setup instruction in
SKILL.md. curlretrieves the current contents ofhttps://cli.oomol.com/install.sh.- The response is streamed immediately to Bash without verification or review.
- If the installer source or delivery pipeline has been compromised, attacker-controlled shell commands execute under the current user's privileges.
- Those commands can access data available to that user, modify user-owned files and configuration, install additional components, or invoke any other permissions available to the process.
Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the user ...[truncated 465 chars]
- The Agent attempts to use the Skill and receives an
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation pattern from Agent-executable instructions. - Treat the CLI as a user-installed prerequisite and require explicit user approval before performing any installation.
- Pin installation instructions to a specific, immutable CLI release rather than a mutable installer URL.
- Download the installer or release artifact to disk without executing it automatically.
- Verify a pinned SHA-256 or stronger digest obtained through an independently trusted channel.
- Prefer a cryptographically signed release and validate the publisher signature before execution.
- Display the artifact, version, source, requested privileges, and expected filesystem changes to the user before running it.
- Execute installation with ordinary user privileges unless elevation is demonstrably necessary and separately approved.
- Prefer a trusted platform package manager with signature verification and version pinning where available.
- Remove the
