T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:68- Finding
Unverified Remote Installation Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 68-76
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable code:
markdown - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions retrieve mutable scripts from an external server and pass their contents directly to a command interpreter. Neither command pins a release, validates a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded payload before execution.
The URLs use HTTPS and are hosted on a domain consistent with the declared OOMOL provider, but transport encryption alone does not establish payload integrity over time. The effective code can change after this Skill has been reviewed. A compromise of the distribution server, its deployment pipeline, its TLS credentials, or another trusted component in the delivery chain could convert the documented installation flow into arbitrary local code execution.
Installation is presented as a conditional recovery step rather than an operation performed during every invocation. This reduces exposure frequency but does not eliminate the execution risk. Installing the CLI is relevant to the Skill's operation, but immediate pipe-to-shell execution is not the minimum privilege or safest mechanism necessary to perform that installation.
Attack Path
- The
ooCLI is absent, causing anoo: command not founderror. - The agent or user follows the first-time setup instructions.
- The command downloads the current contents of
install.shorinstall.ps1. - The downloaded content is passed directly to ...[truncated 1057 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashandirm | iexinstallation paths. - Direct users to a version-pinned release artifact from an authenticated official release channel.
- Download the installer to a local file rather than piping it directly into an interpreter.
- Publish and verify a cryptographic signature or a checksum obtained through a separately authenticated channel.
- Display the resolved version, source, checksum, and intended changes before requesting explicit installation approval.
- Prefer a signed operating-system package or established package manager with integrity verification.
- Run installation with ordinary user privileges whenever possible and document any operation that genuinely requires elevation.
- Pin the CLI version known to be compatible with this Skill and define an explicit, separately approved upgrade procedure.
- Remove the direct
