T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:65- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 65–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand pass their contents directly to a command interpreter. Neither installation path pins a release version, validates a cryptographic checksum or publisher signature, nor gives the user an opportunity to inspect the downloaded file before execution.HTTPS protects the connection in transit but does not establish that the delivered script is immutable or safe. Compromise of the hosting domain, publishing credentials, web infrastructure, DNS resolution, or installer release process could cause arbitrary attacker-controlled commands to execute. The effective payload can also change after the Skill itself has been reviewed.
Installing the CLI may be relevant when
oois unavailable, but immediate remote execution is not the minimum privilege or minimum-risk mechanism required to install it. The Skill’s normal connector operations only require invoking an already installedoocommand.Attack Path
- A Superchat operation fails because the
ooCLI is not installed. - The Agent or user follows the documented first-time setup fallback.
- The shell or PowerShell retrieves the current installer from
cli.oomol.com. - A compromised or maliciously replaced response is supplied by the remote distribution infrastructure.
bashoriexexecutes the response immediately without integrity validation or review.- The payload performs arbitrary actions with the privileges and environment of the invoking Agent or user.
Impact Assessment
Successful exploitat ...[truncated 648 chars]
- A Superchat operation fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove both direct execution pipelines (
curl | bashandirm | iex). - Prefer an official operating-system package manager or a verified publisher repository.
- Pin installation instructions to a specific CLI release rather than a mutable generic installer URL.
- Download the installer or release artifact to a local file before execution.
- Publish a cryptographic checksum or digital signature through a separately trusted channel and verify it locally.
- Fail closed if checksum or signature verification does not succeed.
- Display the source, version, destination, and expected changes, then obtain explicit user approval before installation.
- Run installation with ordinary user privileges unless a specific operation demonstrably requires elevated access.
- Document the files, network endpoints, and configuration changes made by the installer.
- Keep installation outside automatic Skill execution; if
oois missing, provide safe manual setup guidance rather than executing a remote installer.
- Remove both direct execution pipelines (
