T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 59–63
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The setup instructions pipe remotely retrieved content directly into Bash or PowerShell. The installer is not pinned to an immutable release, and the instructions do not verify a cryptographic signature or checksum before execution. Consequently, the effective code executed by this Skill can change after the reviewed package has been published or audited.
HTTPS protects the connection in transit but does not guarantee that the current server-side payload is trustworthy or unchanged. Compromise of the distribution server, hosting account, release process, DNS infrastructure, or TLS credentials could turn the documented installation command into an arbitrary-code execution channel.
Installing a supporting CLI may be relevant to the declared TomTom connector functionality, but immediate execution of an unverified, mutable script is not the minimum privilege or safest installation method necessary to provide that functionality.
Attack Path
- The
ooCLI is absent from the user's system. - An Agent or user follows the first-time setup instructions in
SKILL.md. - The shell retrieves the current installer from
cli.oomol.com. - The pipeline executes the response immediately without saving it for inspection or verifying its integrity.
- If the remote source or delivery infrastructure has been compromised, attacker-controlled commands execute under the invoking user's account.
- Those commands can access data and perform operations available to that account, and may obtain broader system access if the installer prompts for or is run with elevated privilege ...[truncated 793 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashandirm | iexinstallation patterns. - Direct users to an official, documented release page or trusted operating-system package manager.
- Pin installation instructions to a specific reviewed CLI version rather than a mutable installer endpoint.
- Require the installer or package to be downloaded to disk before execution so it can be inspected.
- Publish a SHA-256 or stronger digest through an independently protected channel and verify it before running the installer.
- Prefer cryptographic release signatures and document verification against a pinned, trusted signing key.
- Run installation with ordinary user privileges whenever possible, requesting narrowly scoped elevation only for operations that demonstrably require it.
- Keep the existing behavior of attempting connector actions before presenting setup instructions, but require explicit user approval before downloading or executing any installer.
- For managed environments, recommend centrally reviewed and administratively distributed CLI packages instead of runtime installation from the network.
- Remove the
