T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58-62
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: Highbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions retrieve mutable scripts from
cli.oomol.comand pass their contents directly to Bash or PowerShell. The downloaded code is therefore executed before the user can inspect it. The instructions do not pin a release, verify a cryptographic checksum or signature, or otherwise establish that the retrieved content matches an audited version.HTTPS protects the connection in transit but does not protect against compromise of the hosting account, web server, publishing pipeline, or signing authority. Because the installer source is not included in the project, its behavior and effective privileges cannot be assessed from this package. Its payload may also change after the Skill has been reviewed.
These commands are presented only as fallback installation steps when
oois unavailable, rather than being run during every action. That reduces exposure frequency but does not remove the arbitrary-code execution risk when setup is required.Attack Path
- A user attempts to use the Skill without the
ooCLI installed. - The documented fallback directs the user to run one of the remote installation commands.
- An attacker compromises the remote installer, its hosting or release pipeline, or another component capable of controlling the returned response.
- The attacker substitutes malicious shell or PowerShell content for the legitimate installer.
bashorieximmediately interprets the response without integrity validation or review.- The malicious payload executes with all permissions available to the invoking user.
Impa
...[truncated 869 chars]
- A user attempts to use the Skill without the
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashandirm | iexexecution patterns. - Refer users to a documented package-manager installation method or a version-pinned release artifact from an authenticated release channel.
- Require the installer to be downloaded to a local file before execution so it can be inspected:
bash curl -fSLo oo-install.sh "https://example.invalid/releases/vX.Y.Z/install.sh" - Publish a cryptographic digest through an independently protected channel and verify it before execution:
bash echo "<expected-sha256> oo-install.sh" | sha256sum --check - - Prefer signed release artifacts and verify the publisher's signature using a pinned, documented public key.
- Pin an explicit CLI version instead of retrieving a mutable generic installer.
- Execute installation with ordinary user privileges unless a narrowly defined operation genuinely requires elevation. Clearly disclose every filesystem location and configuration item the installer changes.
- For PowerShell, apply the same download, signature or hash verification, inspection, and separate execution process rather than passing the network response directly to
Invoke-Expression.
- Remove the direct
