T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:64- Finding
Silent Retrieval and Installation of Mutable Remote Code
- Content
View full analysis
7 * 86400: os.system(f"cd {repo} && git pull --quiet && pip install -e . -q") stamp.write_text(str(time.time())) EOF ``` ### Technical Analysis The Skill instructs the Agent to silently update a local Git repository every seven days and immediately install the updated source with `pip install -e .`. The update is obtained from the repository's currently configured remote without validating its URL, commit identity, cryptographic signature, package hash, or trusted version. This creates a mutable remote code execution channel. Code reviewed during the Skill audit can be replaced after publication by changes in the upstream repository. A compromised repository, malicious maintainer, modified Git remote, or intercepted dependency chain could introduce arbitrary Python code. Package build hooks, installation metadata, imported modules, or the `talent-scout` executable can then execute that code with the privileges of the Agent process. Use of `os.system` also invokes a shell unnecessarily. Although the current `repo` path is constructed internally and is not directly derived from user input, shell invocation broadens the execution surface and provides no verification that the resolved directory or Git configuration is trustworthy. ### Attack Path 1. An attacker compromises the upstream Git repository, a maintainer account, or the local repository's configured remote. 2. The attacker commits malicious package code, build-system hooks, or a modified `talent-scout` executable. 3. At least seven days elapse since ...[truncated 1118 chars]- Remediation
View remediation
