T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:18- Finding
Unverified Remote Installer Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:18-20; the same unsafe installation command is displayed byscripts/local-researcher-quickstart.py:31-34
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighComplete Code Snippet (
SKILL.md:18-20):bash # Linux curl -fsSL https://ollama.com/install.sh | shRelated Code Snippet (
scripts/local-researcher-quickstart.py:31-34):python print("📥 安装指南:") print(" macOS: brew install ollama") print(" Linux: curl -fsSL https://ollama.com/install.sh | sh")Technical Analysis
The installation instructions pipe data fetched from an external URL directly into a shell. The payload is not pinned to a reviewed version and is not validated using a cryptographic hash or signature before execution. Consequently, the code ultimately executed can change after this Skill has been audited.
Ollama is relevant to the Skill's declared local-LLM functionality, and the URL uses Ollama's official HTTPS domain. However, these factors do not remove the execution risk. Compromise of the distribution server, domain, release process, or applicable TLS trust chain could cause arbitrary attacker-controlled commands to be returned and immediately executed.
The Python quick-start script does not execute the installer itself; it prints the same command for the user to copy and run. Nevertheless, it promotes the same unsafe installation path.
This behavior exceeds the minimum privileges necessary to provide installation guidance. The Skill can instead direct the user to a pinned package or require separate download, verification, inspection, and execution steps.
Attack Path
- An attacker compromises the remote installer, its hosting infrastructure, the upstream release process, or a trusted network/certificate component.
- The user follows the instructions in
SKILL.mdor copies the command printed by the quick ...[truncated 1035 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shcommand from both the documentation and the quick-start output. - Prefer an official package manager or a versioned, signed Ollama release.
- Pin the installer or package to a specific reviewed version rather than a mutable URL.
- Download the artifact as a separate operation and verify its publisher signature or documented SHA-256 digest before execution.
- Display the verification procedure and expected digest in the installation instructions.
- Execute installation with ordinary user privileges wherever possible, requesting narrowly scoped elevation only when required.
- If a script-based installer remains necessary, instruct users to download and inspect it before running it rather than piping it directly into a shell.
- Remove the
