T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Shell Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 58
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup procedure downloads a mutable shell script from an external server and pipes it directly into Bash. The downloaded content is not displayed for review, pinned to a version, checked against a cryptographic hash, or verified using a digital signature before execution.
The
-f,-s, and-Soptions affect HTTP failure and output handling but do not establish the integrity or provenance of the script itself. HTTPS protects the connection in transit under normal conditions, but it does not protect against compromise of the hosting service, CDN, DNS or certificate trust path, or the publisher's release infrastructure. It also does not prevent the remote script from changing after this Skill has been audited.Installation is only presented as a fallback when
oois unavailable, and obtaining a CLI is relevant to the declared connector functionality. However, immediate execution of unverified network content exceeds the minimum privilege necessary to document or install that dependency. The installer receives the full operating-system privileges of the account running the command.Attack Path
- An attacker compromises the installer host, CDN, publishing pipeline, or another trusted delivery component for
cli.oomol.com. - The attacker replaces or modifies
install.shwith commands that perform unauthorized actions. - A user encounters the documented
oo: command not foundcondition and follows the fallback installation instruction. curlretrieves the attacker-controlled response and passes it directly to Bash without an integrity check or review step.- Bash executes the payload with the invoking user's privileges.
...[truncated 984 chars]
- An attacker compromises the installer host, CDN, publishing pipeline, or another trusted delivery component for
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashexecution pattern. - Direct users to an official package manager or a version-pinned release artifact from a documented publisher-controlled repository.
- Publish a cryptographic checksum and preferably a signed checksum or release signature through an independently authenticated channel.
- Separate download, verification, inspection, and execution into distinct commands. Abort installation if verification fails.
- Pin the installer or package to a reviewed version rather than downloading a mutable latest script.
- Document the files, permissions, and commands used by the installer so users can assess its privilege requirements.
- Avoid running installation as root. If a specific privileged operation is unavoidable, isolate and document that operation rather than elevating the entire installer.
- Remove the direct
