T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Unverified Remote Installer Download and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62–69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShellTechnical Analysis
The installation instructions download mutable scripts from
cli.oomol.comand immediately execute their contents through Bash or PowerShell. They do not pin a release, validate a cryptographic checksum or signature, save the scripts for inspection, or otherwise establish that the executed content matches a reviewed artifact.HTTPS protects the connection in transit but does not make the remote payload immutable. The effective code can change after the Skill itself has been reviewed. Compromise of the hosting service, publishing process, DNS or certificate infrastructure, or vendor account could therefore turn these installation commands into an arbitrary-code execution channel.
Installing the required CLI is legitimate setup functionality, but executing an unverified network response directly is not the minimum privilege or minimum-risk method needed to provide that functionality.
Attack Path
- The
oocommand is unavailable, causing the user or agent to consult the first-time setup instructions. - The user or agent runs the documented Bash or PowerShell installation command.
- The command retrieves the current script from
cli.oomol.com. - The response body is passed directly to a command interpreter without integrity verification or prior inspection.
- A compromised or maliciously changed response executes arbitrary commands with the privileges of the invoking account.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's privileges. The payload could read or alter user-accessible files, collect credentials or en ...[truncated 454 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove direct
curl | bashandirm | iexexecution patterns. - Prefer a trusted package manager with a pinned, versioned CLI release.
- If script-based installation is unavoidable:
- Download the installer to a local file without executing it.
- Pin an exact installer version or immutable artifact URL.
- Publish and verify a cryptographic checksum and preferably a vendor signature.
- Inspect or present the downloaded script before execution.
- Require explicit user approval before running the verified installer.
- Execute with ordinary user privileges unless elevation is demonstrably necessary.
- Document the expected publisher identity, checksum/signature verification commands, and the filesystem or configuration changes made by installation.
- Avoid automatic fallback installation by an agent; return a clear setup error and let the user perform the verified installation separately.
- Remove direct
