T03 · Remote Payload Retrieval and Execution
- Location
INSTALL.md:15- Finding
Remote-controlled binary retrieval and execution through a mutable release manifest
- Content
View full analysis
Vulnerability Details
File Location:
INSTALL.md, lines 15-27
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
The following is an English translation of the relevant installation instructions; the executable commands are reproduced exactly:
text 1. Read `latest.json` from the repository root. 2. Select the entry in `assets[*]` matching the current platform. 3. Download the ZIP using `download_url`. 4. Calculate the ZIP's SHA-256 and compare it with `assets[*].sha256`. 5. Extract the ZIP and enter the extracted skill root directory. 6. Open `SKILL.md` and `INSTALL.md` from the extracted package. 7. Run the bundled program to confirm that it works: ./assets/bin/skillscan version ./assets/bin/skillscan review /path/to/skill ./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-outTechnical Analysis
The installation workflow obtains both the executable download location and its expected SHA-256 digest from the same remotely maintained
latest.jsonmanifest. A checksum proves only that the downloaded file matches the value in that manifest; it does not establish publisher authenticity when the payload and checksum share the same trust boundary.If the release branch, repository account, release-hosting account, or manifest-delivery channel is compromised, an attacker can replace both
download_urlandsha256. The documented validation will then accept the attacker's ZIP, after which the Agent is explicitly instructed to execute the extracted binary.The reviewed artifact does not contain
latest.json,assets/bin/skillscan, or the binary's source code. AlthoughSKILL.mdandassets/build/build-info.jsonstate an expected checksum, the executable itself is absent, so its contents and behavior cannot be independently audited from this package.Attack Path
- An attacker compromises the account, branch, rele ...[truncated 1582 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not obtain the payload URL and sole trust decision from the same mutable manifest.
- Pin the approved release URL, version, archive digest, and platform mapping in the reviewed skill package.
- Sign release artifacts or manifests with a detached cryptographic signature and verify them using a public key distributed through a separate, trusted channel.
- Restrict downloads to an explicit allowlist of HTTPS hosts and reject redirects to unapproved domains.
- Require explicit user confirmation before downloading, extracting, or executing any native binary.
- Extract archives into a newly created restricted directory and reject absolute paths, parent-directory traversal, symlinks, and unexpected executable files.
- Include the corresponding source code and reproducible build instructions so reviewers can verify that the published binary matches the audited source.
- Run the scanner with least privilege in a sandbox that limits filesystem access, credentials, environment variables, process creation, and network access.
- Fail closed if signature verification, checksum validation, platform matching, or provenance validation cannot be completed.
- Ensure documentation consistently describes external-engine behavior and never enables external execution or dependency installation without explicit user authorization.
