T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Remote Installation Script Executed Directly Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 59
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxTechnical Analysis
The installation command retrieves a mutable script from an external URL and passes it directly to Bash. The payload is executed without a pinned version, cryptographic checksum, publisher-signature verification, or opportunity for local review.
Although installation of the
ooCLI supports the Skill's stated functionality and the domain is consistent with the declared OOMOL integration, executing a remotely hosted script is not the minimum-privilege installation method. The repository does not establish what commands the remote script performs, and its contents can change after the Skill has been reviewed. The downloaded payload receives the full permissions of the user running the command, which extends beyond the Skill's declared runtime allowance ofBash(oo *).Attack Path
- A user or Agent attempts to use the Skill on a system where the
ooCLI is unavailable. - The command fails with
oo: command not found. - The fallback instructions cause the installation command to be executed.
- The current content of
https://cli.oomol.com/install.shis downloaded. - Bash executes the content immediately without integrity or authenticity verification.
- If the hosting account, domain, DNS/TLS path, or installation script has been compromised, attacker-controlled commands execute with the invoking user's privileges.
Impact Assessment
A malicious remote payload could execute arbitrary commands with the privileges of the invoking user. Depending on those privileges and the host configuration, it could read or modify accessible files, steal credentials, alter shell configuration, install additional software, or establish persistence. Running the command thr ...[truncated 275 chars]
- A user or Agent attempts to use the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Do not pipe downloaded content directly into a shell.
- Distribute the CLI through a trusted, versioned package manager or a pinned release artifact.
- Download the installer as a file without executing it, then verify a publisher signature and a pinned SHA-256 digest.
- Pin an explicit installer or CLI version so the reviewed artifact cannot change silently.
- Permit inspection of the downloaded script before execution.
- Document the files, permissions, and configuration changes made by the installer.
- Run installation with ordinary user privileges unless a narrowly defined operation explicitly requires elevation.
- Keep installation outside automated Skill execution and require informed user approval before running any installer.
