T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:66- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Twelve Data connector, but its setup instructions direct users to execute remote installer scripts directly in a shell.
Review the setup path before installing. Prefer an official, version-pinned, signed or checksum-verified oo CLI installer instead of running a downloaded script directly in Bash or PowerShell, and only connect the Twelve Data account you intend this skill to use.
SKILL.md:66Unverified Remote Shell Script Execution on macOS and Linux
SKILL.md:70Unverified Remote PowerShell Script Execution on Windows
The skill instructs users to install software by piping a remotely fetched script directly into a shell (curl ... | bash). If the install endpoint, CDN path, TLS trust chain, or upstream distribution is compromised, arbitrary code would execute immediately on the user's machine with the user's privileges.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description says to use this skill for "ANY Twelve Data request" and "Whenever a task involves Twelve Data," which is a broad activation condition without clear boundaries or exclusions. In a manifest, this can cause unintended invocation for loosely related mentions of Twelve Data rather than specific connector actions.
No suspicious patterns detected.