T03 · Remote Payload Retrieval and Execution
- Location
references/troubleshooting.md:128- Finding
Unverified Remote Installation Scripts Executed Directly by Shells
- Content
View full analysis
Vulnerability Details
File Location:
references/troubleshooting.md, lines 128–131
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable Code
bash # Linux/macOS curl -LsSf https://astral.sh/uv/install.sh | sh # Windows PowerShell powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"Technical Analysis
The documented commands retrieve mutable scripts from an external URL and immediately execute the returned content using
shor PowerShell'sInvoke-Expression. They provide no opportunity to inspect the payload and perform no release-version pinning, cryptographic signature verification, or checksum validation.The PowerShell command also uses
-ExecutionPolicy ByPass, disabling an applicable process-level safeguard while executing the downloaded script. Althoughastral.shappears associated with the recommendeduvtool, reliance on the apparent legitimacy of a domain does not eliminate the supply-chain risk. Compromise of the upstream server, hosting infrastructure, DNS resolution, TLS trust chain, or installation script could turn the documented operation into arbitrary code execution without requiring changes to the reviewed Skill package.This behavior exceeds the minimum privileges and capabilities needed for the Skill's declared Python environment-management functionality. The project already documents
python3 -m venvas a built-in fallback, so executing an unverified remote installer is not necessary to create a Python virtual environment.Attack Path
- A user invokes the Skill to create or repair a Python environment.
- The Skill determines that
uvis unavailable. - The troubleshooting instructions direct the agent or user to run one of the remote installation commands.
- The command retrieves the current response from
https://astral.sh/uv/install.shorhttps://astral.sh/uv/install.ps1. - The response is passed directly t ...[truncated 935 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both direct download-to-shell examples from the troubleshooting documentation.
- Default to the built-in and locally available fallback when
uvis absent:bash python3 -m venv .venv source .venv/bin/activate - Prefer a trusted platform package manager that supports version pinning and package verification.
- If direct upstream installation is unavoidable:
- Pin a specific release rather than using a mutable installation endpoint.
- Download the artifact to a local file without executing it.
- Verify its publisher signature or a SHA-256 checksum obtained through an independent trusted channel.
- Allow the user to inspect the downloaded content.
- Clearly disclose the source, version, destination, and commands that will be executed.
- Request explicit user confirmation before execution.
- Execute with ordinary user privileges and never request unnecessary administrator or root access.
- Do not use PowerShell
-ExecutionPolicy ByPasswith remotely retrieved content. Use signed scripts and the narrowest execution policy compatible with the verified installation procedure.
