T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 57–61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from
cli.oomol.comand pass their contents directly to Bash or PowerShell. Neither installation path pins a version, validates a cryptographic checksum, verifies a digital signature, nor gives the user an opportunity to inspect the downloaded script before execution.Consequently, the code ultimately executed is not the code reviewed in this Skill. It can change whenever the remote resource changes. Compromise of the hosting infrastructure, CDN, DNS resolution, deployment process, or TLS trust chain could cause arbitrary attacker-controlled commands to run.
Installing a required CLI can be legitimate, and these instructions are only presented as a fallback when
oois unavailable. However, immediate remote-script execution exceeds the minimum privileges necessary to document or invoke the connector. The Skill could instead stop and direct the user to a verifiable, version-pinned installation procedure.Attack Path
- The
oocommand is unavailable, causing the Agent or user to consult the first-time setup instructions. - The Agent or user executes the documented Bash or PowerShell command.
- The command downloads the current installer from the external OOMOL endpoint.
- The downloaded response is passed directly to a local command interpreter without integrity verification.
- If the endpoint or delivery chain has been compromised, attacker-controlled commands execute with the privileges of the invoking process.
Impact Assessment
A malicious installer could obtain all perm ...[truncated 684 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandirm | iexinstallation instructions. - Prefer a trusted platform package manager and pin the CLI to an explicitly reviewed version.
- If a standalone artifact is necessary, download it as a separate step from a versioned, immutable release URL.
- Publish and verify a cryptographic checksum and, preferably, a digital signature whose trust key is distributed through an independent channel.
- Abort installation if signature or checksum verification fails.
- Allow the user to inspect the downloaded artifact before execution and obtain explicit approval before running an installer.
- Execute installation with ordinary user privileges unless elevated privileges are demonstrably required.
- Document the expected files, network destinations, and system changes made by the installer.
- In automated Agent workflows, report that the CLI is missing and request user-directed installation rather than automatically executing remote setup code.
- Remove all
