T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:69- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 69–73
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve mutable scripts from external URLs and immediately execute them with Bash or PowerShell. They do not pin a script version, verify a cryptographic digest or signature, save the script for inspection, or otherwise establish that the downloaded content matches an audited release.
HTTPS protects content while it is in transit but does not eliminate the risks of a compromised hosting server, deployment pipeline, maintainer account, or signing infrastructure. Because the downloaded script can be changed after this Skill has been reviewed, its effective behavior is not bounded by the contents of the audited project.
Installing the
ooCLI may support the Skill's declared Shortcut functionality, but direct execution of an unverified remote payload exceeds the minimum mechanism necessary for installation. A pinned and cryptographically verified package or artifact would provide a narrower trust boundary.Attack Path
- The
oocommand is unavailable, causing the agent or user to consult the first-time setup instructions. - An attacker compromises the external script host, its publishing pipeline, or an authorized publishing account.
- The attacker replaces
install.shorinstall.ps1with a malicious payload. - The documented command downloads the current payload without integrity or authenticity verification.
- Bash or PowerShell immediately executes the attacker-controlled content with the privileges of the invoking account.
- The payload can access resources available to that account and may install addi ...[truncated 753 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation patterns. - Prefer a trusted platform package manager with a version-pinned package and documented publisher identity.
- If standalone artifacts are required, pin an explicit release version and download the installer to a local file rather than piping it directly into a shell.
- Publish a SHA-256 digest through an independently protected release channel and verify it before execution.
- Cryptographically sign release artifacts and require signature verification against a documented, pinned publisher key.
- Display or inspect the verified script before execution and require explicit user approval before installing software.
- Run installation with ordinary user privileges wherever possible; do not request administrator or root privileges unless a specific installation step demonstrably requires them.
- Document the files, executables, network endpoints, and configuration changes made by the installer so users can assess its scope.
- Keep the existing instruction not to install proactively, ensuring setup occurs only after a genuine missing-command failure and explicit user authorization.
- Remove the
