T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:55- Finding
Unverified Remote Installer Execution Through Shell Interpreters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand immediately execute the responses with Bash or PowerShell. The process does not pin a release, save the scripts for inspection, verify a cryptographic signature, or compare them against trusted checksums.HTTPS protects data in transit but does not establish that the hosted scripts are trustworthy or immutable. Compromise of the hosting infrastructure, publisher account, domain, DNS path, or content delivery system could replace either installer with an arbitrary payload. Because the project only contains
SKILL.md, the actual installer behavior cannot be audited from the submitted artifact.Although installing the required CLI may support the declared Tripadvisor functionality, automatic execution of unverified remote content exceeds the minimum privilege needed to invoke read-only Tripadvisor connector actions. Installation should be a separate, explicit, and verifiable user-controlled operation.
Attack Path
- The
oocommand is unavailable on the target system. - The Agent or user follows the documented first-time setup instructions.
- The shell retrieves a mutable installer from
cli.oomol.com. - A compromised server or delivery path supplies attacker-controlled content with a successful HTTP response.
- Bash or PowerShell executes that content immediately without inspection or integrity verification.
- The payload performs arbitrary actions with the privileges of the invoking Agent or user.
Impact Assessment
Successful exploitation provides arbitrary code execution under the invo ...[truncated 424 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove all pipe-to-interpreter installation commands, including both
curl | bashandirm | iex. - Direct users to an official, signed package-manager distribution where possible.
- Pin installation instructions to a specific reviewed CLI version rather than a mutable latest installer.
- Download the installation artifact to a local file without executing it automatically.
- Publish and verify a cryptographic signature from a trusted release key and a hard-coded SHA-256 checksum obtained through an independent trusted channel.
- Allow the user to inspect the downloaded file and require explicit approval before execution.
- Run installation with ordinary user privileges unless a narrowly defined operation requires elevation; do not request broad administrative access by default.
- Document the files, network destinations, and system changes produced by installation.
- Keep setup separate from normal Skill execution. Authentication or missing-command errors should result in instructions to the user, not autonomous software installation.
- Prefer commands conceptually equivalent to the following verified workflow:
bash curl -fL -o oo-installer.sh "https://trusted.example/releases/vX.Y.Z/install.sh" echo "<trusted-sha256> oo-installer.sh" | sha256sum -c - # Inspect the file and obtain explicit user approval before: bash oo-installer.shA publisher signature should be verified in addition to a checksum wherever possible.
- Remove all pipe-to-interpreter installation commands, including both
