T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Scripts Executed Directly by System Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–62
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from external URLs and immediately execute their contents with Bash or PowerShell. Neither command pins an installer version, validates a cryptographic checksum or signature, nor provides an inspection step before execution.
Although installing the
ooCLI supports the Skill’s declared connector functionality, piping an unverified network response directly into a shell is not the minimum-risk installation method. The effective code executed on a user’s system can change after the Skill has been reviewed.An attacker who compromises the installer host, its deployment pipeline, the relevant domain, or another part of the network trust chain could replace the installer with arbitrary commands. Those commands would execute with the privileges of the user running the installation.
Attack Path
- The
oocommand is unavailable, causing the user or agent to follow the first-time setup instructions. - Bash or PowerShell requests a mutable installer from
cli.oomol.com. - An attacker with control over the installer delivery path supplies a modified response.
- The response is passed directly to
bashoriexwithout integrity verification or review. - The attacker-controlled commands execute locally with the invoking user’s privileges.
Impact Assessment
Successful exploitation permits arbitrary code execution in the invoking user’s security context. The resulting scope may include reading or modifying user-accessible files, stealing locally available credentials or session data, installing persistence, executing additional payloads, and makin ...[truncated 284 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace direct
curl | bashandirm | iexexecution with installation through a trusted operating-system package manager where possible. - Pin the CLI to a specific reviewed release rather than retrieving a mutable generic installer.
- Download the installer or release artifact to disk without executing it automatically.
- Publish and verify a cryptographic checksum and, preferably, a signature using a key distributed through an independent trusted channel.
- Separate download, verification, inspection, and execution into distinct commands.
- Require explicit user approval immediately before executing any downloaded installer.
- Document whether elevated privileges are needed and instruct users not to run the installer as an administrator or root unless strictly required.
- Prefer signed, reproducible release artifacts from the project’s official release repository.
- Replace direct
