T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56-60
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup instructions download mutable scripts from
cli.oomol.comand execute the responses immediately using Bash or PowerShell. The commands do not pin an installer version, verify a cryptographic checksum or signature, or give the user an opportunity to inspect the downloaded content before execution.Although the installation domain appears associated with the CLI vendor, the effective code executed on a user's machine can change after this Skill has been reviewed. Compromise of the hosting infrastructure, publishing credentials, DNS resolution, TLS termination, or installer delivery pipeline could therefore turn the documented setup process into an arbitrary-code-execution channel.
Installing a CLI may legitimately require local changes, but direct execution of an unverified network response exceeds the minimum privilege and assurance needed to support TinyURL creation and listing. The Skill itself only needs access to the constrained
oocommands declared inallowed-tools; unrestricted installer execution is a substantially broader capability.Attack Path
- A user or agent attempts to use the Skill on a system where the
ooCLI is unavailable. - The command fails with
oo: command not found, causing the user to follow the documented first-time setup instructions. - An attacker compromises or gains control over the remote installer delivery path, such as the hosting service or publishing account.
- The
curlorirmcommand retrieves the attacker-controlled response. - Bash or PowerShell executes that response immediately without integrity or authenticity veri ...[truncated 958 chars]
- A user or agent attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation commands. - Keep CLI installation outside ordinary Skill execution and require an explicit, user-controlled setup action.
- Direct users to a version-pinned release artifact or trusted platform package manager.
- Download the installer to a local file rather than executing the network response directly.
- Publish a cryptographic SHA-256 digest and require verification before execution.
- Prefer signed artifacts and validate the signature against a documented, trusted publisher key.
- Allow users to inspect the downloaded script before running it.
- Document the exact files, permissions, network destinations, and system changes performed by the installer.
- Advise users not to execute the installer with elevated privileges unless a documented operation strictly requires them.
- Pin the CLI to a reviewed version and define a separate, explicit process for upgrades.
A safer installation pattern would follow this sequence:
bash curl -fL -o install.sh "https://cli.oomol.com/releases/<pinned-version>/install.sh" echo "<trusted-sha256> install.sh" | sha256sum --check - less install.sh bash install.shThe checksum must be obtained through a trusted, authenticated release channel rather than from the same mutable location as the installer.
- Remove the
