T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:77- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 77–81
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions retrieve scripts from an external server and pass their contents directly to Bash or PowerShell. The downloaded payload is not pinned to a specific release and is not verified using a cryptographic checksum or digital signature before execution.
Although installing the
ooCLI supports the Skill's declared SmugMug functionality and the download domain is associated with the declared publisher, executing a mutable network response directly is not the minimum privilege or safest installation mechanism necessary. HTTPS protects data in transit but does not prevent malicious execution if the hosting infrastructure, DNS resolution, publishing account, CDN, or installer itself is compromised.Because the effective installer payload can change after the Skill has been reviewed, the commands create a remote code-execution channel outside the audited project contents. The audit found no evidence that the current remote scripts are malicious; the vulnerability is the absence of an integrity and review boundary before execution.
Attack Path
- A user or Agent attempts to use the Skill on a system where the
ooCLI is unavailable. - The command fails with
oo: command not found. - The Skill directs the user or Agent to run the applicable installation command.
- The shell retrieves the current installer from
cli.oomol.com. - If the remote script, hosting service, publishing credentials, CDN, or network resolution has been compromised, attacker-controlled content is returned.
- Bash or PowerShell immediately executes th ...[truncated 940 chars]
- A user or Agent attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandInvoke-RestMethod | Invoke-Expressioninstallation instructions. - Prefer a trusted platform package manager with a pinned CLI version and verifiable package provenance.
- If a standalone installer is required, download it to a local file without executing it:
- Use a version-specific, immutable artifact URL.
- Publish and verify a SHA-256 or stronger digest.
- Verify a detached digital signature against a documented, trusted public key.
- Abort installation if any integrity check fails.
- Allow the user to inspect the downloaded script before execution.
- Require explicit user approval before installing software or running any installer.
- Run installation with ordinary user privileges whenever possible; do not request administrator or root privileges unless a documented component strictly requires them.
- Document the expected files, directories, network destinations, and permission changes made by the installer.
- Pin the expected
ooCLI version so subsequent changes to the remote installer cannot silently alter reviewed behavior.
- Remove all
