T03 · Remote Payload Retrieval and Execution
- Location
scripts/check-ollama-memory.sh:90- Finding
Unverified Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
scripts/check-ollama-memory.sh:90;SKILL.md:83
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
scripts/check-ollama-memory.sh:90:bash curl -fsSL https://ollama.com/install.sh | shSKILL.md:83:bash curl -fsSL https://ollama.com/install.sh | shTechnical Analysis
The installation workflow downloads mutable content from an external endpoint and passes it directly to
sh. The retrieved code is not pinned to a reviewed version and is not verified using a checksum or cryptographic signature.HTTPS provides transport protection, but it does not establish that the current response is identical to the script reviewed when this Skill was published. A compromise of the remote host, its deployment pipeline, DNS or certificate infrastructure, or an unexpected upstream modification could therefore change the code executed by this Skill.
Installing Ollama is relevant to the declared functionality and the executable path requires the explicit
--installoption. Nevertheless, directly piping a remote response into a shell exceeds the minimum safe privilege and trust boundary necessary to install the software. The documentation also encourages users to reproduce the same unsafe command manually.Attack Path
- A user or Agent invokes
scripts/check-ollama-memory.sh --install, or follows the installation command inSKILL.md. - The script requests the current content of
https://ollama.com/install.sh. - The response is immediately supplied to
shwithout local review, version pinning, checksum validation, or signature verification. - If the endpoint or delivery chain has been compromised or unexpectedly modified, attacker-controlled commands execute in the local shell.
- Those commands can access and modify resources available to the invoking account and may attempt to obtain additional ...[truncated 670 chars]
- A user or Agent invokes
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shpipeline from both the executable script and documentation. - Prefer a trusted operating-system package repository or another package manager that supports signed metadata and version pinning.
- If a vendor installer must be used:
- Download it to a newly created temporary file with restrictive permissions.
- Pin an expected installer version or immutable artifact URL.
- Verify a vendor-published cryptographic signature or checksum obtained through an independent trusted channel.
- Fail closed if verification cannot be completed.
- Allow the user to inspect the downloaded file before execution.
- Execute it as a separate, explicit step only after informed consent.
- Do not automatically elevate privileges. Explain any required privilege level and request approval at the point of elevation.
- Record the verified version and digest so the installation process is reproducible and auditable.
- Remove the direct
