T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:59- Finding
Unverified Remote Installer Is Piped Directly into a Command Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent waboxapp connector skill, with a real setup caution around piping a remote installer into a shell but no evidence of hidden or malicious behavior.
Install only if you trust OOMOL and waboxapp. Before using the first-time setup commands, consider installing the oo CLI through a verified release or package manager instead of piping a downloaded script directly into a shell, and review every outgoing WhatsApp payload before approving write actions.
SKILL.md:59Unverified Remote Installer Is Piped Directly into a Command Shell
The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (curl ... | bash). This bypasses basic integrity review and creates a supply-chain execution path where a compromised host, MITM, or malicious script update could lead to arbitrary code execution on the machine running the skill.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
No suspicious patterns detected.