External Script Fetching
- Category
- Supply Chain
- Confidence
- 80% confidence
- Finding
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- Content
Publish a file: one call, no account
bash curl -sS https://chorus.host/v1/publish -H 'X-Chorus-Client: claude-code/2.0' -F file=@index.htmlThe response is JSON:
url,claimUrl,claimToken,expiresAt, andfileUrl(the direct link when you sent one file). A single.htmlfile becomes the home page whatever it's called. More files: repeat-F file=@path(use-F "file=@app.js;filename=js/app.js"to keep a folder path), or zip the folder and send-F archive=@site.zip. Add-F slug=my-siteto pick the subdomain,-H 'Accept: text/plain'to get only the link. Up to 4 MB of files per call without an API key, 10 MB with one; bigger sites use the three calls below.
