T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:22- Finding
Unverified Remote Installation Script Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 22
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://tunelo.net/install.sh | shTechnical Analysis
The installation command retrieves a mutable shell script from an external server and immediately passes its contents to
sh. The project does not pin the installer to an immutable version, validate a cryptographic signature or checksum, or provide the installer source for inspection.Although HTTPS protects the connection in transit, it does not protect against compromise of the hosting server, domain or deployment credentials, nor against the script being intentionally changed after this Skill has been reviewed. Consequently, the effective code executed by this instruction cannot be determined from the audited project.
Piping the response directly into a shell also prevents normal inspection before execution. The documentation states that the resulting binary may be installed at
/usr/local/bin/tunelo, indicating that the external installer may perform a system-wide installation. The installer and binary were not included in the project, so their precise behavior, integrity, persistence mechanisms, and data handling could not be audited.Attack Path
- An Agent or user follows the installation instruction in
SKILL.md. curlrequests the current content ofhttps://tunelo.net/install.sh.- The external hosting infrastructure, domain, or deployment account is compromised, or the remotely hosted script is otherwise modified.
- The server returns attacker-controlled shell commands.
- The pipe sends those commands directly to
shwithout integrity verification or review. - The commands execute with all permissions available to the invoking account.
- If the Agent or user invoked the installation in an elevated context, the payload may modify system-wide fil ...[truncated 970 chars]
- An Agent or user follows the installation instruction in
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shinstallation pattern. - Publish versioned release artifacts through a reputable package registry or an immutable release URL.
- Pin the documentation to an exact release version rather than retrieving a mutable installer.
- Publish SHA-256 checksums through an independently protected channel and verify the downloaded artifact before execution.
- Prefer cryptographic signature verification using a documented public signing key.
- Download the installer to a local file first, verify its integrity, and make it available for inspection before running it.
- Include the installer source and relevant build instructions in the auditable project.
- Install into a user-owned directory by default and avoid requesting administrative privileges unless a specific system-wide installation is explicitly required.
- Document every filesystem, network, and privilege change performed by the installer.
- For subsequent tunnel usage, require explicit confirmation of the exact directory or port being exposed and default public tunnels to authenticated access such as
--private.
- Remove the direct
