T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installation Scripts Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–67
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions retrieve mutable content from remote OOMOL endpoints and immediately pass it to a command interpreter. Neither command pins the downloaded script to an immutable release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the payload before execution.
TLS protects the connection in transit but does not protect users if the hosting service, DNS resolution, publishing account, build pipeline, or remote installation script is compromised. Because the effective executable payload is controlled remotely, it may change after this Skill has been reviewed.
Installing the required CLI supports the declared functionality, but immediate
curl | bashorirm | iexexecution is not the minimum-risk installation method. The same functionality can be provided through signed packages or separately downloaded and verified artifacts.Attack Path
- The
ooCLI is absent, and an attempted connector operation fails withoo: command not found. - The user or agent follows the documented first-time setup instructions.
- An attacker compromises the installation endpoint, its publishing pipeline, or another component capable of changing the returned script.
curlorirmretrieves the attacker-controlled response.- The pipe sends the response directly to Bash or PowerShell without integrity validation or review.
- The malicious script ...[truncated 700 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace direct download-to-shell execution with installation through a trusted operating-system package manager or a signed release package.
- Pin the CLI to a specific immutable version rather than a mutable installation endpoint.
- Publish cryptographic checksums and signed provenance for every supported artifact.
- Download the artifact to a local file, verify its signature and checksum, and only then execute it.
- Require explicit user approval before installation and clearly describe the commands and privileges involved.
- Avoid running the installer with administrator or root privileges unless a documented component strictly requires them.
- If bootstrap scripts must remain available, publish their source in a version-controlled repository and reference a commit-pinned version.
