T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unverified Remote Installer Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 57–61
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from
cli.oomol.comand immediately execute them using Bash or PowerShell. Neither command pins a specific installer version nor verifies a cryptographic signature or expected checksum before execution.HTTPS protects the connection in transit, but it does not protect users if the hosting infrastructure, publishing account, DNS configuration, or installer itself is compromised. It also does not ensure that the script executed in the future is the same script that was available when this Skill was audited. The remote server therefore controls the effective code executed by these instructions.
Installing the CLI may be necessary when
oois unavailable, but passing unreviewed network content directly to an interpreter grants that content all permissions held by the invoking process. This exceeds the minimum safe installation mechanism.Attack Path
- The
oocommand is unavailable and an agent or user follows the documented first-time setup procedure. - An attacker compromises or otherwise gains control over the remote installer content served from
cli.oomol.com. curlorInvoke-RestMethodretrieves the attacker-controlled script.- The shell pipeline passes the response directly to Bash or
Invoke-Expressionwithout integrity verification or inspection. - The malicious script executes with the permissions of the user or agent that launched the command.
- The script can perform any operation available under those permissions, including modifying files, accessing ...[truncated 712 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Replace direct pipe-to-shell installation with a version-pinned package or release artifact obtained from an authenticated release channel.
- Publish expected SHA-256 checksums or cryptographic signatures through a separately protected channel and require verification before execution.
- Download the installer to a local file rather than sending its response directly to an interpreter.
- Allow the user to inspect the downloaded file and require explicit approval before executing it.
- Execute installation with the least privileges necessary and avoid requesting administrator or root access unless a documented installation step strictly requires it.
- Prefer an operating-system package manager with package signing and version locking where supported.
- Document the exact installer version tested with this Skill and fail safely if integrity verification does not succeed.
