T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62–66
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions download mutable scripts from an external server and immediately execute their contents using Bash or PowerShell. Neither command pins a specific installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded code before execution.
Consequently, the effective installer payload can change after the Skill has been reviewed. Compromise of the hosting domain, deployment pipeline, DNS or TLS trust chain could replace the expected installer with arbitrary executable code. A transient server error or unexpected response could also be passed directly to the command interpreter.
The installation behavior is conditional on the
ooCLI being unavailable and uses an OOMOL-branded HTTPS domain, but those factors do not establish the integrity of the retrieved payload. Direct remote-script execution also exceeds the normal tool scope declared asBash(oo *). Although installing the required CLI may be necessary, piping an unverified response into a shell is not the minimum privilege or safest installation method.The Skill's ordinary network operations through
oo connector runare consistent with its declared TemplateFox integration. No evidence was found that it accesses local secrets or covertly exfiltrates information. The confirmed issue is specifically the unverified installer execution channel.Attack Path
- A TemplateFox operation fails because the
ooCLI is not installed. - The Agent or user follows the documented first-time setup instructions.
...[truncated 1015 chars]
- A TemplateFox operation fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands.
- Prefer a trusted operating-system package manager or an official, signed release package.
- Pin the installer or package to an explicit version rather than retrieving a mutable latest script.
- Download the artifact to disk without executing it automatically.
- Publish and verify a SHA-256 checksum obtained through a separately protected channel.
- Verify a cryptographic signature tied to a documented publisher identity.
- Allow the user or Agent operator to inspect the downloaded script before execution.
- Require explicit user approval before installing software or running any installer.
- Execute the installer with the least privileged account possible and avoid requesting administrator privileges unless strictly necessary.
- Keep installation outside the Skill's normal action workflow; the Skill should ordinarily invoke only the already-installed
ooexecutable permitted byBash(oo *).
