T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:55- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–63
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash - **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ```Technical Analysis
The installation instructions retrieve mutable scripts from external URLs and immediately execute the responses using Bash or PowerShell. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the operator an opportunity to inspect the downloaded code before execution.
TLS protects the network connection in transit, but it does not guarantee that the remote host will always return the same reviewed payload. Compromise of the hosting service, publishing credentials, DNS infrastructure, or release pipeline could cause arbitrary attacker-controlled code to be executed.
Installing the required CLI may support the declared Workable connector functionality, but direct execution of an unverified network response is not necessary. It grants the remote installer the full permissions of the user running the command and therefore exceeds the minimum capability needed to query Workable records.
Attack Path
- The
ooCLI is unavailable, causing the user or Agent to follow the first-time setup instructions. - The user or Agent runs the documented
curl | bashorirm | iexcommand. - The command retrieves a mutable script from
cli.oomol.com. - An attacker who has compromised the hosting or distribution path causes the server to return a malicious installer.
- Bash or PowerShell executes the response immediately without integrity verification or review. 6 ...[truncated 866 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation commands.
- Direct users to a documented, official installation guide or trusted platform package manager.
- Pin the CLI to a specific reviewed version rather than retrieving a mutable installer.
- Download the release artifact without executing it immediately.
- Publish and verify a SHA-256 checksum and, preferably, a cryptographic signature issued by a documented release key.
- Ensure verification fails closed before any installer or binary is executed.
- Run installation with ordinary user privileges unless elevated privileges are demonstrably required.
- If a script-based installer must remain available, instruct users to save and inspect it first, while still requiring signature or checksum validation before execution.
A safer conceptual workflow is:
bash curl -fSLo oo-installer.sh "https://trusted.example/releases/<pinned-version>/install.sh" echo "<published-sha256> oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.shThe artifact URL and expected digest must come from a trusted, authenticated release process and must be pinned to a specific version.
