T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:54- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions retrieve mutable scripts from external URLs and pass their contents directly to command interpreters. The Bash command pipes the HTTP response into
bash, while the PowerShell command passes it toInvoke-Expression.Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded payload before execution. HTTPS protects the connection in transit but does not establish payload immutability or protect against compromise of the hosting infrastructure, publishing account, DNS configuration, or installer build pipeline.
Installing the required CLI is related to first-time setup, but immediate execution of an unverified remote response exceeds the minimum mechanism necessary. A separately downloaded and cryptographically verified installer would provide the same functionality with materially lower risk.
Attack Path
- An attacker compromises the installer host, deployment pipeline, publishing credentials, DNS resolution, or another part of the remote distribution chain.
- The attacker modifies
install.shorinstall.ps1to include malicious commands. - The
oocommand is unavailable, causing the documented first-time setup path to be used. - The shell retrieves the attacker-controlled response.
- The pipe to
bashoriexexecutes the response immediately without integrit ...[truncated 568 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandirm | iexinstallation instructions. - Direct users to a version-pinned release hosted through an authenticated official release channel.
- Download the installer to a local file without executing it automatically.
- Publish and require verification of a SHA-256 or stronger checksum over a secure, independently authenticated channel.
- Prefer cryptographic release signatures and require verification against a documented, pinned signing key.
- Use a trusted operating-system package manager where packages and repository metadata are signed.
- Display the exact installer version and source to the user and require explicit approval before execution.
- Run installation without administrative privileges unless a specific installation step demonstrably requires elevation.
- Document how users can inspect the downloaded installer before running it.
- Remove all
