T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:60- Finding
Unverified Remote Shell Script Execution on macOS and Linux
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for using ZeroBounce through OOMOL, but its first-time setup tells users to execute unverified remote installer scripts directly in a shell.
Review the oo CLI installation method before installing. Prefer a signed or checksum-verified installer from the vendor rather than running the pipe-to-shell commands as written, and avoid sending sensitive or bulk email data through the connector unless OOMOL's data handling terms meet your needs.
SKILL.md:60Unverified Remote Shell Script Execution on macOS and Linux
SKILL.md:64Unverified Remote PowerShell Script Execution on Windows
SKILL.md:25ZeroBounce Request Data Is Mandatorily Routed Through an Additional Third Party
The skill instructs users to install software by piping a remote script directly into a shell (curl ... | bash), which executes unverified code from the network with the user's privileges. If the install endpoint, transport, hosting, or upstream distribution is compromised, this can lead to arbitrary code execution and full environment compromise.
oo: command not found — install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):
curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux
This markdown skill description defines invocation scope in very broad terms without examples or exclusions. The phrasing could overlap with many incidental mentions of ZeroBounce and does not clearly distinguish when the skill should or should not activate.
No suspicious patterns detected.