T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command retrieves a mutable script from an external URL and pipes it directly into Bash. The downloaded content is not pinned to a reviewed version and is not validated using a cryptographic signature or a pinned checksum before execution.
HTTPS provides transport protection but does not establish that the script remains identical to the version reviewed during this audit. Compromise of the hosting service, its deployment pipeline, associated accounts, or other upstream infrastructure could replace the installer. The substituted payload would then execute immediately without an opportunity for inspection.
Installing the CLI may be necessary when it is absent, but executing unverified network content directly is not the minimum-privilege installation method required by the Skill's Cert Spotter functionality.
Attack Path
- The
ooCLI is unavailable and an authentication or connection operation requires it. - The agent or user follows the documented first-time setup command.
- An attacker who controls or compromises the remote installer endpoint or its publishing pipeline substitutes malicious shell content.
curldownloads the substituted content.- The shell pipeline passes the content directly to Bash without signature, checksum, version, or source verification.
- Bash executes the attacker's commands with all privileges available to the invoking user.
Impact Assessment
A successful exploit provides arbitrary command execution under the invoking user's account. The payload could read or modify accessible files, collect local credentials and tokens, alter application configuration, install additi ...[truncated 345 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation instruction. - Prefer an official operating-system package manager or a pinned release artifact from a verifiable official repository.
- Pin the CLI to an explicitly reviewed version rather than retrieving a mutable latest installer.
- Download the artifact to disk without executing it automatically.
- Verify a publisher-provided cryptographic signature or a securely distributed, version-specific SHA-256 digest before installation.
- Display or otherwise make the downloaded installer available for inspection before execution.
- Run installation with ordinary user privileges wherever possible and request elevation only for narrowly defined installation steps.
- Document the expected download origin, version, checksum, files installed, and required permissions.
- Remove the direct
