T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:130- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This DeerFlow management skill is coherent, but it tells users to run high-impact installation and update commands with weak verification and limited safety guidance.
Review commands before running them. Prefer pinned DeerFlow releases or verified commits, inspect downloaded installer scripts before execution, avoid sudo -E for remote scripts, back up config.yaml/.env/logs before uninstall or update cleanup, and do not paste raw API keys into chat or store them in broadly readable files.
SKILL.md:130Unverified Remote Installer Scripts Are Executed Directly
SKILL.md:165Mutable Upstream Repository Code Is Executed Without Version or Integrity Pinning
SKILL.md:38API Key Collection and Plaintext Configuration Lack Secret-Handling Safeguards
This finding captures the dangerous composition of fetching remote content and immediately executing it with elevated privileges. The chaining is what makes the issue severe: users are not given a chance to inspect the script, and any compromise of the source leads directly to root-level code execution.
sudo apt install -y curl git make nginx python3.12 python3-pip
# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm
This is another pipe-to-shell chaining pattern, here without sudo but still allowing immediate execution of network-fetched code. In a skill meant to guide installation, such one-liners increase the chance that users run unreviewed commands verbatim, making supply-chain attacks practical.
npm install -g pnpm
curl -fsSL https://astral.sh/uv/install.sh | sh
**Windows (WSL2 推荐):**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd "$INSTALL_DIR"
# 3. 创建配置文件
cp .env.example .env
cp config.example.yaml config.yaml
# 4. 编辑 config.yaml,添加模型配置
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
make config-upgrade
# 3. 重建 venv
cd backend && rm -rf .venv && uv sync && cd ..
# 4. 重新安装依赖
make install
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd ~/deer-flow
# 2. 创建配置文件(从模板复制)
cp .env.example .env
cp config.example.yaml config.yaml
# 3. 编辑 config.yaml,添加模型配置
The matched rm -rf ~/deer-flow is a real destructive command that permanently removes the installation directory and all contents. In a deployment-management skill, such commands are contextually relevant but still risky because they encourage direct execution of irreversible filesystem operations.
make clean
cd ~ && rm -rf ~/deer-flow
### 更新步骤
The matched rm -rf ~/deer-flow is a real destructive command that permanently removes the installation directory and all contents. In a deployment-management skill, such commands are contextually relevant but still risky because they encourage direct execution of irreversible filesystem operations.
make clean
cd ~ && rm -rf ~/deer-flow
### 更新步骤
Chaining cd ~ && rm -rf ~/deer-flow combines navigation and destruction into a single command, reducing the chance that a user pauses to verify state before deletion. In operational documentation, command chaining around destructive actions increases the likelihood of accidental misuse and makes review harder.
make clean
cd ~ && rm -rf ~/deer-flow
### 更新步骤
The chained update command cd backend && rm -rf .venv && uv sync && cd .. bundles a destructive step with follow-on actions, which can obscure what is being removed and prevent users from validating necessity first. In an agent skill, compact chained commands are more likely to be run without scrutiny, raising the risk of accidental environment loss or partial update failures.
make config-upgrade
cd backend && rm -rf .venv && uv sync && cd .. make install
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
INSTALL_DIR="$HOME/deer-flow" CONFIG_FILE="$INSTALL_DIR/config.yaml" ENV_FILE="$INSTALL_DIR/.env" LOG_DIR="$INSTALL_DIR/logs"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux (Ubuntu/Debian):
# 安装系统依赖
sudo apt update
sudo apt install -y curl git make nginx python3.12 python3-pip
# 安装 Node.js 和 pnpm
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux (Ubuntu/Debian):
# 安装系统依赖
sudo apt update
sudo apt install -y curl git make nginx python3.12 python3-pip
# 安装 Node.js 和 pnpm
The use of sudo -E preserves environment variables while executing a remote script as root, which broadens risk beyond ordinary sudo. Preserved environment values can influence script behavior or leak sensitive data, and combined with pipe-to-shell execution this becomes a materially dangerous privileged execution pattern.
sudo apt install -y curl git make nginx python3.12 python3-pip
# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm
The use of sudo -E preserves environment variables while executing a remote script as root, which broadens risk beyond ordinary sudo. Preserved environment values can influence script behavior or leak sensitive data, and combined with pipe-to-shell execution this becomes a materially dangerous privileged execution pattern.
sudo apt install -y curl git make nginx python3.12 python3-pip
# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 安装 Node.js 和 pnpm
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
npm install -g pnpm
# 安装 uv
The uninstall flow instructs users to run rm -rf "$INSTALL_DIR" after deriving the path from a variable, but provides no confirmation, backup guidance, or sanity checks. In an agent skill context, destructive commands are more dangerous because the skill may be followed mechanically or automated, increasing the chance of accidental data loss if the variable is wrong or the user has important data under that directory.
The uninstall instructions include a recursive force-delete of the installation directory without any warning about irreversible data loss. In an agent skill context, users may copy-paste commands directly, so omission of a warning increases the risk of accidental destruction of local configuration, logs, or other files if the path is modified or misunderstood.
curl -fsSL https://astral.sh/uv/install.sh | sh executes a remote script directly without inspection or integrity verification. In this installation-oriented skill, that pattern is more dangerous because it normalizes unaudited code execution and creates a supply-chain attack surface if the remote source is compromised.
npm install -g pnpm
curl -fsSL https://astral.sh/uv/install.sh | sh
**Windows (WSL2 推荐):**
The file presents all user-facing instructions in Chinese, which effectively forces a specific language for readers. There is no indication that this is a region-specific document, nor any opt-in or alternative language reference, which may violate language/locale policy expectations.
The update instructions delete the Python virtual environment as part of a chained command but do not warn the user that local packages, caches, and environment state will be removed. While less severe than deleting arbitrary directories, this can still cause avoidable disruption and data loss for users who have custom local setup inside the environment.
No suspicious patterns detected.