T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:25- Finding
Mutable Remote CLI Is Downloaded and Executed Without Version Pinning
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:25-31
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
markdown Use the `npx @coinfello/agent-cli@latest` CLI to interact with CoinFello. The CLI handles smart account creation, SIWE authentication, delegation management, prompt-based transactions, and transaction status checks. ## Prerequisites - Node.js 20 or later (npx is included with Node.js) The CLI is available via `npx @coinfello/agent-cli@latest`. No manual build step is required.The same mutable command is subsequently used throughout the documented workflows:
bash npx @coinfello/agent-cli@latest create_account npx @coinfello/agent-cli@latest sign_in npx @coinfello/agent-cli@latest send_prompt "send 5 USDC to 0xRecipient..." npx @coinfello/agent-cli@latest approve_delegation_requestTechnical Analysis
The Skill instructs the Agent to retrieve and execute the npm package identified by the mutable
latestdistribution tag. The package source is not included in the audited project, and the Skill provides no exact version, integrity digest, signature verification, lockfile, or locally reviewed executable.Consequently, the effective code executed by the Skill can change after this audit without any modification to the reviewed files. This is particularly dangerous because the downloaded CLI is entrusted with cryptocurrency account creation, SIWE authentication, local credential access, signing operations, and submission of token delegations.
Although no evidence establishes that the current package is malicious, the execution model creates a remote payload and supply-chain trust boundary that cannot be verified from this project.
Attack Path
- An attacker compromises the npm publisher account, package build pipeline, registry distribution process, or another dependency used by
@coinfello/agent-cli. - The attack ...[truncated 1401 chars]
- An attacker compromises the npm publisher account, package build pipeline, registry distribution process, or another dependency used by
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version, such as@coinfello/agent-cli@X.Y.Z. - Pin and verify the package tarball integrity using an approved cryptographic digest or npm lockfile integrity value.
- Include the CLI source or a reproducible build definition in the reviewed project so its sensitive behavior can be audited.
- Require signed releases and verify provenance through an appropriate package-signing or build-attestation mechanism.
- Review and pin all transitive dependencies used by the CLI.
- Run the CLI in a constrained environment with access only to the required configuration files, Unix socket, RPC endpoints, and CoinFello API.
- Establish a controlled update process in which new package versions are reviewed before the pinned version is changed.
- Replace
