T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:23- Finding
Mutable and Unverified External Executables and Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:23-35; duplicated inreferences/setup-guide.md:13-18, 37-46
Vulnerability Type: Unverified remote executable retrieval and unpinned dependencies
Risk Level: HighAffected code:
bash python3 -m venv ~/whisper-env && source ~/whisper-env/bin/activate pip install faster-whisper apt install ffmpeg # or brew install ffmpeg on macOSbash mkdir -p ~/piper && cd ~/piper wget https://github.com/rhasspy/piper/releases/latest/download/piper_linux_x86_64.tar.gz tar xzf piper_linux_x86_64.tar.gz mkdir voices && cd voices wget https://huggingface.co/rhasspy/piper-voices/resolve/main/de/de_DE/thorsten_emotional/medium/de_DE-thorsten_emotional-medium.onnx wget https://huggingface.co/rhasspy/piper-voices/resolve/main/de/de_DE/thorsten_emotional/medium/de_DE-thorsten_emotional-medium.onnx.jsonTechnical Analysis
The setup retrieves a native Piper executable through a mutable
latestrelease URL, extracts it, and later instructs the user to execute it. No expected checksum, cryptographic signature, fixed release version, or provenance verification is provided. The Python dependency is also installed without a pinned version or lock file.GitHub and Hugging Face are recognizable upstream hosting services, and the project does not pipe downloaded data directly into a shell. Nevertheless, the effective native payload can change after this Skill has been reviewed. A compromised upstream account, release pipeline, package index, dependency, or mutable release could therefore introduce arbitrary executable code.
Attack Path
- An attacker compromises an upstream release, package, account, or distribution channel.
- The mutable
latestasset or unpinned Python dependency is replaced with a malicious version. - A user follows the documented installation commands without verifying artifact integrity.
- The downloa ...[truncated 596 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
latestwith an explicitly reviewed release version. - Publish and verify an expected SHA-256 or stronger digest before extraction.
- Verify upstream signatures or attestations where available.
- Pin Python packages to reviewed versions and use a hash-locked requirements file.
- Install dependencies only from explicitly configured, trusted indexes.
- Fail installation when integrity verification does not succeed.
- Document the expected archive layout and validate extracted paths to prevent archive path traversal.
- Run the resulting executable as a dedicated, unprivileged account inside a restricted service sandbox.
- Replace
