T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–64
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand immediately execute their contents with Bash or PowerShell. There is no version pinning, checksum validation, cryptographic signature verification, local review step, or sandboxing between retrieval and execution.HTTPS provides transport encryption and server authentication, but it does not guarantee that the retrieved script remains identical to the version assessed during this audit. If the hosting server, DNS infrastructure, certificate trust chain, or upstream release pipeline is compromised, the downloaded response can contain arbitrary commands. The
curl | bashandirm | iexconstructions execute that response without giving the user a meaningful opportunity to inspect it.Installing the
ooCLI may be necessary when it is absent, but immediate execution of an unpinned remote response exceeds the minimum safe privileges needed to provide installation guidance. The Skill can instead direct users to a pinned, independently verifiable release artifact.The project contains no local implementation of the downloaded installers, so their behavior and requested privileges cannot be verified from the audited package.
Attack Path
- A user or agent attempts to use the WakaTime Skill on a system where the
ooCLI is unavailable. - The resulting
oo: command not foundcondition causes the first-time setup instructions to be followed. - An attacker compromises or influences the installation endpoint, its deployment pipeline, DNS resolution, or another trusted delivery component. ...[truncated 1117 chars]
- A user or agent attempts to use the WakaTime Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove both direct download-to-shell command patterns.
- Publish versioned installation artifacts through a verifiable official release channel and pin an exact
ooCLI version. - Require users to download the artifact as a separate step rather than piping it directly into an interpreter.
- Publish SHA-256 checksums through an independently protected channel and require checksum verification before execution.
- Cryptographically sign release artifacts and document signature verification using a pinned, trusted public key.
- Give users an explicit opportunity to inspect the downloaded installer before running it.
- Prefer a trusted platform package manager with signed metadata and version pinning where available.
- Document the installer's expected filesystem changes, network destinations, and privilege requirements. Installation should run without administrative privileges unless a specific system-level operation strictly requires elevation.
- If an installer script remains necessary, use a version-specific immutable URL and fail closed when signature or checksum validation fails.
- Keep installation a user-initiated recovery step; the agent should not automatically download or execute an installer following a command failure.
