T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:67- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 67–76
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The first-time setup instructions download mutable scripts from an external server and immediately execute them through Bash or PowerShell. Neither command pins an installer version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded content before execution.
The Skill package therefore does not contain the effective installation payload that will execute. Its behavior may change after the Skill has been reviewed. A compromise of the download server, publication process, hosting account, DNS resolution, or another relevant supply-chain component could replace the legitimate installer with attacker-controlled commands.
Although installation is only recommended after an
oo: command not founderror, downloading and blindly executing a remote script is not the minimum privilege or safest mechanism necessary to install the CLI.Attack Path
- A user invokes the Skill on a system where the
ooCLI is unavailable. - The command fails with
oo: command not found. - The Skill directs the user or agent to execute the documented first-time setup command.
- The command retrieves the current installer from
cli.oomol.com. - Bash or PowerShell executes the response without integrity or authenticity verification beyond transport security.
- If the remote payload or its delivery infrastructure has been compromised, attacker-controlled code executes with the permissions of the user who launched the shell.
Impact Assessment
Exploitation permits arbitrary command execution under the i ...[truncated 607 chars]
- A user invokes the Skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove both pipe-to-shell installation patterns, including
curl | bashandInvoke-RestMethod | Invoke-Expression. - Direct users to a trusted, version-pinned package or official release artifact instead of a mutable installer URL.
- Download the artifact as a separate step without executing it automatically.
- Publish and require verification of a SHA-256 digest and, preferably, a platform-native publisher signature before installation.
- Use a constrained platform package manager where possible, with an exact package identity and version.
- Present the commands the installer will perform and require explicit user approval before execution.
- Run installation with ordinary user permissions unless a specific operation demonstrably requires elevation; isolate any privileged step and explain its purpose.
- Retain the existing behavior of attempting ordinary connector actions before suggesting setup, but make installation a user-controlled process rather than an agent-executed fallback.
- Remove both pipe-to-shell installation patterns, including
