T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The installation instructions retrieve mutable scripts from `cli.oomol.com` and pass their contents directly to a command interpreter. The Bash command pipes the downloaded response into `bash`, while the PowerShell command executes it through `Invoke-Expression` (`iex`). Neither instruction pins a release version, verifies a cryptographic signature or checksum, nor provides an opportunity to inspect the downloaded script before execution. Consequently, the code actually executed can differ from the content available when the Skill was audited. If the remote hosting infrastructure, publishing account, DNS resolution, or relevant TLS trust path is compromised, an attacker could replace the installer with arbitrary commands. The commands would execute with all privileges available to the user running the Skill. Although installation is presented only as a fallback when the CLI is absent, downloading and immediately executing an unverified remote payload exceeds the minimum privilege and trust necessary to provide installation guidance. ### Attack Path 1. The `oo` executable is unavailable, causing a command-not-found failure. 2. The Agent or user follows the documented first-time setup procedure. 3. The shell requests `install.sh` or `install.ps1` from the remote OOMOL endpoint. 4. An attacker controlling or compromising the delivery endpoint, publishing process, DNS path, or trusted network path substitutes malicious script content ...[truncated 956 chars]- Remediation
View remediation
/install.sh" printf '%s %s\n' "" "oo-install.sh" | sha256sum --check - less oo-install.sh bash oo-install.sh ``` Equivalent integrity and signature checks should be required for the PowerShell installation path. ]]>
