Back to skill

Security audit

llm-verify

Security checks for vulnerabilities and agentic risk

Overview

The skill’s endpoint-checking purpose is coherent, but its README recommends executing mutable remote installer scripts directly in a shell and describes a broad installer that can write to every detected AI tool.

Review before installing. The skill instructions themselves are coherent, but do not run the README’s pipe-to-shell or Invoke-Expression installers unless you separately trust and verify the fetched scripts. Prefer a ClawHub install or an immutable signed release, and use the targeted install-skill options instead of writing to every detected AI tool by default.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:10
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

markdown
## Install

```bash
curl -fsSL https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.sh | sh

On Windows: irm https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.ps1 | iex

text

### Technical Analysis

The documented installation commands download scripts from the mutable `main` branch of a personal GitHub repository and immediately execute them using a local shell.

The Unix command pipes the HTTP response directly into `sh`, while the Windows command passes the response to PowerShell's `Invoke-Expression`. Neither workflow gives the user an opportunity to inspect the downloaded script before execution. No immutable release version, commit hash, expected checksum, or cryptographic signature is specified.

The remote `install.sh`, `install.ps1`, executable binary, and corresponding implementation source are not included in the audited package. Consequently, the actual installation behavior cannot be verified from this artifact. The effective payload can also change after the Skill package has been reviewed without requiring any modification to the reviewed files.

This behavior is not necessary for the Skill's declared endpoint-verification functionality. Installation requires obtaining the executable, but it does not require directly executing mutable network content. The approach therefore exceeds the minimum trust and execution privileges necessary for installation.

### Attack Path

1. A user follows the installation instructions in `README.md`.
2. The shell retrieves the current installer from the repository's mutable `main` branch.
3. The downloaded response is immediately interpreted as shell or PowerShell code without integrity or authenticity verification.
4. If the hosting account, repository, branch, release process, or delivere
...[truncated 1301 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh and Invoke-Expression installation instructions.
  2. Publish immutable, versioned release artifacts rather than retrieving installers from a mutable branch.
  3. Provide SHA-256 checksums through an independently protected release manifest and require users to verify them before execution.
  4. Cryptographically sign release artifacts and document signature verification using an established mechanism such as Sigstore or GPG.
  5. Use a download-verify-execute workflow that stores the installer locally and allows inspection before execution.
  6. Pin documentation to a specific release version or immutable commit rather than main.
  7. Include the installer source and relevant binary source in the reviewable project so installation behavior can be audited.
  8. Make installation target-specific and least-privileged. Do not write to every detected AI tool by default; require an explicit target and show a preview of proposed filesystem changes.
  9. Document all files, directories, and permissions modified by installation and provide a complete uninstall procedure.
  10. Advise users not to run installation with administrator or root privileges unless a narrowly defined operation demonstrably requires them.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping downloaded content directly into sh is a classic unsafe command chain that turns any upstream compromise into immediate arbitrary command execution. In the context of a developer tool that may be installed on workstations or CI agents, this can lead to credential theft, persistence, source-code tampering, or broader environment compromise.

Content

Scanner excerpt · README.md (reported line 12)May include surrounding context.

Install

bash
curl -fsSL https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.sh | sh

On Windows: irm https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.ps1 | iex

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

Credentials can live in .env or the environment instead, leaving only the model on the command line:

bash
# .env
LLM_VERIFY_BASE_URL=https://api.anthropic.com
LLM_VERIFY_API_KEY=sk-ant-...
LLM_VERIFY_MODEL=claude-opus-4-5

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to download and immediately execute remote scripts from GitHub using curl | sh and irm ... | iex. This removes any opportunity to inspect the installer, pin its integrity, or verify provenance, so a compromised repository, account, branch, or network path could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The documentation fetches an external installer script at runtime from a mutable remote location. Even before the shell execution aspect, this creates a supply-chain trust problem because the fetched content can change over time or be replaced if the source is compromised.

Content

Scanner excerpt · README.md (reported line 12)May include surrounding context.

Install

bash
curl -fsSL https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.sh | sh

On Windows: irm https://raw.githubusercontent.com/asale-ai/llm-verify/main/install.ps1 | iex

Static analysis

No suspicious patterns detected.