T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:65- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for managing WebScraper.io through OOMOL, but its fallback setup tells agents to execute mutable remote installer scripts directly in a shell.
Review this skill before installing if you do not already trust OOMOL's installer path. Prefer installing the oo CLI through a verified, versioned, user-controlled process, and only allow write or delete WebScraper.io actions after checking the exact target and payload.
SKILL.md:65Unverified Remote Installation Scripts Executed Directly by Shells
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which creates a classic remote code execution path if the hosting domain, TLS chain, CDN, or script contents are compromised. Because this appears in a 'first-time setup' section of an operational skill, an agent may follow it during error recovery, making the dangerous pattern reachable in normal use.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
The description defines activation in extremely broad terms without narrowing context, exclusions, or example trigger boundaries. Because SKILL.md is a markdown file, this falls under vague triggers and could cause unintended invocation whenever WebScraper.io is merely mentioned.
No suspicious patterns detected.