T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The installation instructions download mutable scripts from external URLs and immediately execute them using Bash or PowerShell. They do not pin an installer version, verify a cryptographic checksum or digital signature, or give the user an opportunity to inspect the downloaded content. The Skill therefore delegates its effective installation behavior to infrastructure outside the audited package. A compromise of the OOMOL download domain, hosting environment, publication pipeline, DNS resolution, or another relevant delivery component could replace the installer after this Skill has been reviewed. Installing the required CLI is relevant to the declared Shippo connector functionality, but piping an unverified response directly into a command interpreter exceeds the minimum execution behavior necessary to perform that installation safely. ### Attack Path 1. A Shippo operation fails because the `oo` CLI is not installed. 2. The user or agent follows the first-time setup instructions in `SKILL.md`. 3. `curl` or `Invoke-RestMethod` retrieves the current installer from `cli.oomol.com`. 4. The response is passed directly to Bash or `Invoke-Expression` without integrity or authenticity verification beyond transport security. 5. If the remote script or its delivery infrastructure has been compromised, attacker-controlled commands execute with the privileges of the user running the installation. 6. Those commands can access resources available to th ...[truncated 917 chars]- Remediation
View remediation
/install.sh" echo " oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.sh ``` The real implementation should use an official pinned release URL and an independently verifiable signature or checksum. The PowerShell installation process should provide equivalent download, signature verification, inspection, and explicit-execution stages. ]]>
