T03 · Remote Payload Retrieval and Execution
- Location
README.md:10- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
markdown ## Install ```bash curl -fsSL https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.sh | shOn Windows:
irm https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.ps1 | iextext ### Technical Analysis The documented installation commands download scripts from the mutable `main` branch of a personal GitHub repository and immediately execute them using a local shell. The Unix command pipes the HTTP response directly into `sh`, while the Windows command passes the response to PowerShell's `Invoke-Expression`. Neither workflow gives the user an opportunity to inspect the downloaded script before execution. No immutable release version, commit hash, expected checksum, or cryptographic signature is specified. The remote `install.sh`, `install.ps1`, executable binary, and corresponding implementation source are not included in the audited package. Consequently, the actual installation behavior cannot be verified from this artifact. The effective payload can also change after the Skill package has been reviewed without requiring any modification to the reviewed files. This behavior is not necessary for the Skill's declared endpoint-verification functionality. Installation requires obtaining the executable, but it does not require directly executing mutable network content. The approach therefore exceeds the minimum trust and execution privileges necessary for installation. ### Attack Path 1. A user follows the installation instructions in `README.md`. 2. The shell retrieves the current installer from the repository's mutable `main` branch. 3. The downloaded response is immediately interpreted as shell or PowerShell code without integrity or authenticity verification. 4. If the hosting account, repository, branch, release process, or delivere ...[truncated 1301 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shandInvoke-Expressioninstallation instructions. - Publish immutable, versioned release artifacts rather than retrieving installers from a mutable branch.
- Provide SHA-256 checksums through an independently protected release manifest and require users to verify them before execution.
- Cryptographically sign release artifacts and document signature verification using an established mechanism such as Sigstore or GPG.
- Use a download-verify-execute workflow that stores the installer locally and allows inspection before execution.
- Pin documentation to a specific release version or immutable commit rather than
main. - Include the installer source and relevant binary source in the reviewable project so installation behavior can be audited.
- Make installation target-specific and least-privileged. Do not write to every detected AI tool by default; require an explicit target and show a preview of proposed filesystem changes.
- Document all files, directories, and permissions modified by installation and provide a complete uninstall procedure.
- Advise users not to run installation with administrator or root privileges unless a narrowly defined operation demonstrably requires them.
- Remove the
