T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions pipe a remotely downloaded, mutable shell script directly into Bash. The command does not pin an immutable release, verify a cryptographic checksum or publisher signature, or provide an opportunity to inspect the downloaded content before execution.
HTTPS protects the connection in transit under normal conditions, but it does not establish that every future version of the remote installer is safe. Compromise of the hosting service, publishing account, DNS infrastructure, or installer-generation pipeline could cause arbitrary attacker-controlled commands to execute when the setup instruction is followed.
Installing the required CLI is related to the Skill's declared functionality. However, executing an unverified remote response directly in a shell exceeds the minimum trust and execution privileges necessary to perform that installation.
Attack Path
- The
oocommand is unavailable, causing the Agent or user to follow the first-time setup instructions. - An attacker compromises or gains control over
https://cli.oomol.com/install.shor its delivery infrastructure. - The attacker replaces or modifies the installer response with malicious shell commands.
curlretrieves the attacker-controlled response.- The pipe passes the response directly to Bash without integrity verification or review.
- Bash executes the payload with the privileges of the user running the command.
Impact Assessment
A malicious installer can execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the surrounding environment, it could read or modify accessible files, steal environment credentials or ap ...[truncated 210 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation pattern. - Prefer a signed operating-system package repository or a verified official package manager.
- Pin installation instructions to a specific immutable CLI version.
- Download the installer or release artifact to a local file without executing it.
- Verify the artifact using a hardcoded SHA-256 digest obtained through a separate trusted release channel.
- Where supported, verify a publisher signature whose public key is independently distributed and pinned.
- Display the source, version, destination paths, and requested permissions before installation.
- Require explicit user approval before executing the verified installer.
- Run installation with ordinary user privileges unless a documented installation step strictly requires elevation.
- Fail closed if signature or checksum validation does not succeed.
A safer workflow is: download a pinned release artifact, verify its signature and checksum, inspect or unpack it into a controlled location, and only then execute or install it after user confirmation.
- Remove the direct
