T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for using TRIGGERcmd, but its first-time setup includes directly executing a remote installer, which needs review before use.
Install only if you are comfortable with OOMOL mediating TRIGGERcmd actions and with reviewing setup manually. Before running the documented installer, prefer an official verified package or inspect and verify the installer yourself; confirm every trigger_command request because it can run saved commands on your connected computer.
SKILL.md:56Unverified Remote Installation Scripts Executed Directly by Shells
The skill instructs the agent to install software by piping a remote script directly into bash, which is a classic supply-chain and remote code execution risk. If the install server, DNS, TLS trust chain, or the script itself is compromised, the agent would execute attacker-controlled code on the host with the user's privileges.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The skill description says to use this skill for ANY TRIGGERcmd request, which creates an overly broad routing trigger and can cause the agent to invoke this skill whenever TRIGGERcmd is mentioned, even when the user did not intend tool execution. In an agent setting, overbroad invocation increases the chance of unintended reads or, after insufficient confirmation, write actions such as triggering commands on connected computers.
No suspicious patterns detected.