T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:68- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 68
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The first-time setup instructions pipe a remotely downloaded installation script directly into Bash. The remote resource is mutable and is neither version-pinned nor checked against a cryptographic checksum or signature before execution. Consequently, the effective code executed by the Skill can change after the package has been reviewed.
Installing the required CLI may be necessary when it is absent, but immediate execution of unverified network content exceeds the minimum safe setup procedure. The audit found no evidence that the referenced domain is intentionally malicious; nevertheless, this delivery pattern creates a remote code-execution channel if the host, account, DNS path, TLS delivery infrastructure, or installer publication process is compromised.
Attack Path
- The
ooCLI is unavailable, causing anoo: command not founderror. - The Agent follows the documented first-time setup procedure.
curlretrieves the current contents ofhttps://cli.oomol.com/install.sh.- The pipe passes the response directly to Bash without saving, reviewing, pinning, or verifying it.
- Bash executes all commands supplied by the remote endpoint with the privileges of the user running the Agent.
- A compromised installer could download additional payloads, access user-readable files, alter shell configuration, or execute any other operation permitted to that user.
Impact Assessment
Successful exploitation provides arbitrary command execution with the invoking user's privileges. The accessible scope may include the user's files, environment variables, local credentials available to that process, shell configuration, and network-accessible ...[truncated 187 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace
curl | bashwith a version-pinned installation artifact from a verifiable official release. - Download the artifact to a local file without executing it.
- Publish and verify a cryptographic checksum and, preferably, a trusted digital signature before execution.
- Display the exact version, source, expected checksum, and intended installation changes to the user.
- Require explicit user approval before installing software.
- Run installation with ordinary user privileges unless elevation is demonstrably required.
- Prefer a trusted platform package manager or signed package that supports version pinning and integrity verification.
- Fail closed when validation fails; do not fall back to executing unverified content.
- Replace
