T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Execution Through Shell Pipelines
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 59–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable code from an external server and pass it directly to Bash or PowerShell. The installer is executed without a pinned release, cryptographic checksum, publisher-signature verification, or local inspection.
HTTPS protects the connection in transit and authenticates the endpoint through the certificate infrastructure, but it does not make the remote payload immutable. A compromised hosting account, origin server, release process, or trust chain could change the code executed after this Skill has been reviewed.
Installation of the
ooCLI is relevant to the declared connector functionality, and the source uses an OOMOL-associated domain. However, immediate execution of an unverified response exceeds the minimum safe mechanism needed to install the dependency. The current installer contents are not included in the project and therefore could not be audited.Attack Path
- A The Cat API operation fails because the
ooCLI is not installed. - The Agent or user follows the first-time setup instructions.
curlorInvoke-RestMethoddownloads the installer currently served bycli.oomol.com.- The response is passed directly to Bash or
Invoke-Expression. - If the remote payload or delivery infrastructure has been compromised, arbitrary commands execute with the permissions of the invoking account.
- The payload could subsequently access local files, credentials available to that account, or install additional components.
Impact Assessment
Successful exploitation provides arbitra ...[truncated 555 chars]
- A The Cat API operation fails because the
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashandirm | iexexecution patterns. - Prefer an official operating-system package manager with package-signature verification.
- Pin the CLI to a specific reviewed release rather than retrieving a mutable latest installer.
- If an installer must be downloaded, save it to disk before execution and provide an opportunity for inspection.
- Publish a SHA-256 digest through a separately protected release channel and verify it before execution.
- Verify a trusted publisher signature where the platform supports signed artifacts.
- Require explicit user approval before installing software or executing any downloaded installer.
- Document the installer's required permissions and instruct users not to run it as an administrator or root unless strictly necessary.
- Prefer commands equivalent to:
bash curl -fSLo oo-installer.sh "https://trusted.example/pinned-release/install.sh" echo "<pinned-sha256> oo-installer.sh" | sha256sum --check less oo-installer.sh bash oo-installer.shThe URL and digest must correspond to a specific immutable, reviewed release.
- Remove the direct
