T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:32- Finding
Unverified Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches a flight-booking purpose, but it tells agents to automatically install and replace executable tooling from remote sources without a separate user approval step.
Review before installing. The booking workflow has sensible payment and passenger-data safeguards, but the skill can automatically install or replace local executable tooling from remote sources. Prefer installing uv and atlas-flight-booking yourself from sources you trust, or only use this skill in an environment where automatic tool installation is acceptable.
SKILL.md:32Unverified Remote Installer Is Downloaded and Executed Directly
SKILL.md:35External CLI Package Is Force-Installed Without Artifact Integrity Verification
The manifest description says to use the skill whenever a user wants to search, compare, verify, choose seats, create and pay for an order, or check status, but it does not define clear trigger phrases, scope limits, or negative examples. This broad natural-language activation could overlap with ordinary travel-planning requests and makes it unclear when this skill should activate versus a general travel assistant.
The skill explicitly instructs the agent to install or upgrade tooling automatically and to avoid asking the user for permission, which authorizes autonomous system modification. In an agent environment, silently fetching installers, changing PATH-adjacent tooling, and continuing execution materially increases the risk of unintended software installation, supply-chain compromise, and execution in a context the user did not clearly approve.
- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.
Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.
Then run `atlas-flight auth status --json`. Retain `data.ticketing_activation_url` and `data.ticketing_blocker` only when returned; never invent or derive either field. If authorization is required, follow `references/cli-contract.md`. Explain that Atlas authorization is required before the interrupted task can continue and present the returned URL as a descriptive clickable link. Briefly explain what the user will do on the page: sign in and authorize with an existing ATRIP account, or choose **Create one**, finish registration, then sign in and authorize. Ask the user to return to the conversation and reply after authorization is complete. Stop the current turn without polling. After the user confirms completion, poll once for at most 120 seconds and resume the interrupted task only after `AUTHORIZED`.
The instruction 'use this Chinese wording' imposes a specific language for a user-facing response path, even though policy requires avoiding forced language or locale constraints without user opt-in. Unlike line 12, which respects the user's language, this section requires Chinese output for a particular case regardless of the user's preference.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Collection rule
Use the verification response as the source of truth. Ask only for fields listed in `data.requirements.required_fields`. Carry each `traveler_id` and `passenger_type` from `data.travelers`; never ask the user to invent IDs. Ask only for missing values, then build the payload for the user.
The order envelope also requires a contact name. Ask for it only if it is not already available from the passenger details. Contact email and mobile are optional unless the user supplies them.
This variant uses wget to stream a remote installer directly into the shell, creating the same arbitrary-code-execution risk as curl|sh. Because the skill also pairs this with instructions to proceed automatically, the danger is amplified in agentic contexts where a user may not see or understand the installation step before execution.
If `uv` is unavailable, detect the operating system and run the applicable official standalone installer:
- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.
Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.
This variant uses wget to stream a remote installer directly into the shell, creating the same arbitrary-code-execution risk as curl|sh. Because the skill also pairs this with instructions to proceed automatically, the danger is amplified in agentic contexts where a user may not see or understand the installation step before execution.
If `uv` is unavailable, detect the operating system and run the applicable official standalone installer:
- macOS or Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`; use `wget -qO- https://astral.sh/uv/install.sh | sh` only when `curl` is unavailable.
- Windows: `powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"`.
Use the newly installed executable in the current session, including `$HOME/.local/bin/uv` on macOS/Linux or `$HOME\.local\bin\uv.exe` on Windows when `uv` is not yet on `PATH`. Run exactly `uv tool install --force --python 3.12 atlas-flight-booking==0.3.12`, using that resolved executable path when the CLI is missing, invalid, or older than the minimum supported version. If `atlas-flight` is not yet on `PATH`, resolve the tool binary directory with `uv tool dir --bin` and invoke `atlas-flight` from there; do not ask the user to restart the terminal. Verify that `atlas-flight --version` now reports `0.3.12` or newer and continue. Only stop when the automatic installation or upgrade actually fails; then give one concise failure explanation and the official `https://docs.astral.sh/uv/getting-started/installation/` link. Do not fall back to another Python environment or package manager.
No suspicious patterns detected.