T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:64- Finding
Unverified Remote Installation Script Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64–68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from an external server and execute them immediately through Bash or PowerShell. The commands do not pin a script version, verify a cryptographic signature or checksum, save the content for inspection, or constrain the installer in a sandbox.
The domains are consistent with the declared OOMOL provider, and installation is presented as a fallback only when
oois unavailable. Nevertheless, the effective code is controlled by the remote endpoint and can change after this Skill has been reviewed. A compromise of the domain, server, DNS path, TLS termination, deployment process, or installer publishing account could therefore turn the documented setup command into an arbitrary-code execution channel.Installing software also exceeds the minimum privileges required for the Skill's ordinary operation, which only needs permission to invoke an already installed
ooCLI using the restrictedBash(oo *)tool declaration. Installation should consequently be treated as a separate, explicitly approved administrative action rather than an automatic Skill fallback.Attack Path
- The
oocommand is absent, causing an agent or user to consult the first-time setup instructions. - An attacker compromises or otherwise gains control over the remote installation script or its delivery infrastructure.
- The victim executes the documented pipe-to-shell command.
- Bash or PowerShell runs the attacker-controlled response immediately, without integrity verification or prior inspection.
- The payload per ...[truncated 958 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexinstallation flows. - Direct users to a version-pinned release artifact from the official release channel.
- Publish and require verification of a cryptographic signature or a checksum obtained through an independently authenticated channel.
- Download the artifact to disk, verify it, and allow inspection before execution.
- Require explicit user approval before installing software; do not let the agent install it automatically after a command failure.
- Prefer a trusted platform package manager with package signing and fixed version constraints where available.
- Run installation with ordinary user privileges unless elevated privileges are demonstrably required, and document every filesystem or configuration change.
- Keep normal Skill execution limited to the declared
oocommand scope and provide a clear failure message when the CLI is unavailable.
- Remove direct
