T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:63- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 63
Vulnerability Type: Remote payload retrieval and execution through a shell pipeline
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation instruction pipes a remotely retrieved shell script directly into Bash. The remote payload is not pinned to an immutable release and is not validated using a cryptographic signature or published checksum before execution. Consequently, the effective code can change after the Skill package has been audited.
Although the URL is presented as the official OOMOL CLI domain, this pattern relies on the continuing integrity of the remote hosting infrastructure, release pipeline, domain, DNS resolution, and TLS trust chain. A compromise of any relevant upstream component could replace the installer with attacker-controlled shell commands.
This behavior exceeds the minimum privileges required for operating the declared TimelinesAI connector. Connector actions only require an already-installed
ooCLI. Automatically executing an unverified installer is a separate code-execution capability and should not occur without explicit user approval and integrity validation.Attack Path
- The
ooCLI is absent, causing an action to fail withoo: command not found. - The agent or user follows the documented first-time setup instruction.
curlretrieves the current contents ofhttps://cli.oomol.com/install.sh.- The response is streamed directly to Bash without being saved, inspected, version-pinned, or verified.
- If the remote server, publishing pipeline, domain resolution, or trusted delivery path has been compromised, attacker-controlled commands execute under the invoking user's account.
- The payload can access resources available to that account and may modify the local environment or install additional co ...[truncated 699 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashpipeline from the Skill instructions. - Prefer a trusted platform package manager or a signed, version-pinned OOMOL CLI release.
- If script-based installation is necessary, download the artifact to a local file without executing it immediately.
- Pin the installer to a specific immutable release rather than a mutable generic URL.
- Verify a publisher signature and a SHA-256 checksum obtained through an independently trusted channel.
- Allow the user to inspect the downloaded script before execution.
- Require explicit user approval before running any installer because installation is outside ordinary TimelinesAI connector operations.
- Run the installer with the least-privileged account possible and document any files, permissions, or system settings it changes.
- Remove the
