T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:61- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 61–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The setup instructions retrieve mutable scripts from an external server and immediately pass their contents to a command interpreter. The Unix command pipes the response into Bash, while the Windows command uses
Invoke-Expressionto execute the downloaded PowerShell content.Neither installation path pins a specific installer version nor verifies a cryptographic checksum or publisher signature. The executed payload is therefore determined by the remote server at installation time and can change after this Skill has been reviewed. Redirect handling and the lack of artifact inspection further prevent the user from confirming what will execute.
Installation is ancillary to the Skill's declared function of invoking the
updown_ioconnector. Automatically executing an unverified installer exceeds the minimum behavior necessary to document or operate that connector.Attack Path
- The
oocommand is unavailable, causing the user or Agent to follow the first-time setup instructions. - An attacker compromises the installer host, its deployment pipeline, or another component capable of controlling the HTTPS-served installer.
- The attacker replaces the installer response with arbitrary shell or PowerShell commands.
curl | bashorirm | iexexecutes the response immediately, without checksum, signature, version, or content verification.- The payload runs with the permissions of the user who ...[truncated 1097 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove direct execution patterns such as
curl | bashandirm | iex. - Prefer an official platform package manager or a version-pinned release artifact from the project's verified release channel.
- Download the installer to a local file without executing it, using a URL that identifies an immutable version.
- Publish expected SHA-256 or stronger checksums through an independently protected channel and require verification before execution.
- Where supported, verify a cryptographic publisher signature using a pinned and documented signing identity.
- Instruct users to inspect the verified installer before running it as a separate command.
- Run installation without administrator or root privileges unless a specific, documented step strictly requires elevation.
- Document the files, permissions, network destinations, and system changes expected from the installer.
- For automated Agent use, treat missing CLI installation as a manual prerequisite rather than authorizing the Agent to fetch and execute remote code automatically.
- Remove direct execution patterns such as
