T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 56
Vulnerability Type: Remote payload retrieval and immediate shell execution
Risk Level: HighTechnical Analysis
The first-time setup instructions download a mutable remote script and pipe it directly into Bash:
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / LinuxThe effective executable content is not included in the reviewed project and therefore cannot be statically audited. The command does not pin a release version, verify a cryptographic signature or checksum, or provide an inspection step before execution.
HTTPS protects the connection in transit under normal conditions, but it does not ensure that the script remains identical to the version intended when the Skill was reviewed. Compromise of the remote server, domain, CDN, TLS termination infrastructure, or publishing process could cause arbitrary replacement content to execute. This behavior exceeds the minimum privileges needed merely to explain how to install the CLI because safer, verifiable installation methods are available.
Attack Path
- The
oocommand is unavailable, causing the user or agent to consult the first-time setup instructions. - An attacker compromises or gains control of the remote installation endpoint or its release pipeline.
- The endpoint returns a modified
install.shpayload. curlstreams that payload directly to Bash without local inspection or integrity verification.- The payload executes with all permissions held by the user running the command.
- The payload may access user-readable credentials and files, alter shell configuration, install additional software, or establish persistence.
Impact Assessment
Successful exploitation permits arbitrary command execution with the invoking user's privileges. The affected scope can include all files, credentials, environment variables, network resources, and applica ...[truncated 432 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace the pipe-to-shell command with a pinned release artifact from an official, documented release repository.
- Download the artifact to a local file rather than sending it directly to Bash.
- Publish and verify a cryptographic signature or a checksum obtained through a separately authenticated channel.
- Pin an explicit CLI version so the reviewed installation payload cannot change silently.
- Allow the user to inspect the downloaded script before execution.
- Require explicit user approval before running any installer.
- Prefer a trusted platform package manager where the package source, version, and signature can be independently verified.
- Document the files, directories, and permissions the installer requires, and run it without administrator privileges unless strictly necessary.
A safer workflow is: download a versioned artifact, verify its publisher signature and expected digest, inspect it, and only then execute it with the least-privileged account required.
