T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:284- Finding
Unpinned External Repository and Dependency Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 284–293
Vulnerability Type: Unverified external source and insecure dependency execution
Risk Level: Highbash git clone https://github.com/yourrepo/calculus-homework-assignment.git # 2. Install dependencies pip install -r requirements.txt # 3. Configure the database python setup_database.py # 4. Start the service python main.py --port 8000Technical Analysis
The deployment instructions tell users to clone an external placeholder repository without pinning an immutable commit or verifying its integrity. They then direct users to install packages from the repository's uncontrolled
requirements.txtfile and executesetup_database.pyandmain.py.The externally referenced repository and executable files are not included in the audited project. Consequently, their source, dependencies, installation hooks, and runtime behavior cannot be reviewed as part of this package. The effective payload may change after this skill has been audited because the instructions retrieve the repository's current state rather than a verified revision.
Python packages installed through
pipmay execute build or installation logic. The subsequent Python commands directly execute code obtained from the external source. Exploitation therefore does not require a vulnerability in the documented sample code: control of the repository, one of its dependencies, or a resolved package may be sufficient.There is no evidence in the audited file that the referenced repository is presently malicious. The risk arises from the unverified retrieval and execution process.
Attack Path
- An attacker gains control of the referenced repository, causes the placeholder repository reference to resolve to attacker-controlled content, or compromises a dependency named in
requirements.txt. - The attacker adds malicious package installation logic, modifies
setup_database.py, or modifiesmain.py. - A user ...[truncated 1441 chars]
- An attacker gains control of the referenced repository, causes the placeholder repository reference to resolve to attacker-controlled content, or compromises a dependency named in
- Remediation
View remediation
Remediation Suggestions
- Replace the placeholder URL with an official, controlled repository.
- Pin the repository to an immutable, reviewed commit instead of cloning and executing the mutable default branch.
- Verify signed commits or release artifacts and publish expected cryptographic checksums.
- Include the actual implementation in the audited skill package where practical, so executable content is reviewed together with its instructions.
- Pin all direct and transitive Python dependencies to reviewed versions.
- Use a hash-locked dependency file and install with
pip --require-hashes. - Retrieve packages only from explicitly approved package indexes; disable unintended fallback indexes.
- Review package source and installation hooks before installation.
- Run installation and application scripts inside an isolated virtual environment or container using a non-privileged account.
- Grant
setup_database.pyonly the minimum database permissions required for schema initialization; do not use administrative or superuser credentials. - Prevent deployment scripts from receiving unrelated secrets through environment variables.
- Require a manual source review and integrity check before executing
setup_database.pyormain.py.
