T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:86- Finding
Unverified Remote Installer Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 86–91
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash # macOS / Linux curl -fsSL https://getcloak.dev/install.sh | sh # Windows (PowerShell) irm https://getcloak.dev/install.ps1 | iexTechnical Analysis
The installation instructions retrieve mutable scripts from an external website and execute them immediately using a shell or PowerShell interpreter. Neither command pins a release version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded code before execution.
The project does not contain a local installer, integrity metadata, or other evidence from which the behavior of these remote scripts can be audited. The trustworthiness and future contents of the referenced URLs therefore cannot be established from the reviewed artifact.
Installing the Cloak utility is relevant to the Skill's declared secret-protection functionality, but direct download-to-interpreter pipelines exceed the minimum-risk mechanism necessary to perform that installation. A verified, versioned package or separately downloaded and authenticated artifact would provide the same functionality with less supply-chain exposure.
Attack Path
- An agent or user follows the installation command in
SKILL.md. - The command connects to
getcloak.devand retrieves the current response from the installer URL. - An attacker who compromises the website, DNS infrastructure, TLS endpoint, publishing process, or installer storage replaces the expected script with a malicious payload.
- The shell or PowerShell interpreter executes the response immediately without integrity verification or prior inspection.
- The payload runs with the privileges of the invoking user and may access user-readable files, install persistence, modify development tools, or steal credentials.
- If installation is per ...[truncated 845 chars]
- An agent or user follows the installation command in
- Remediation
View remediation
Remediation Suggestions
- Remove both direct pipe-to-interpreter installation commands.
- Direct users to a version-pinned package from an authenticated official package repository where possible.
- If standalone installers are required, use a staged process:
- Download a specific release artifact to a local file.
- Obtain its expected SHA-256 digest through a separately authenticated release channel.
- Verify the digest before execution.
- Prefer a cryptographic signature tied to a documented publisher key.
- Inspect the downloaded script before running it.
- Execute it explicitly only after successful verification and informed user approval.
- Publish immutable, versioned installer URLs rather than mutable
install.shandinstall.ps1endpoints. - Document that installation should occur as a non-privileged user unless a specific operation demonstrably requires elevation.
- Require agents to ask for explicit user consent before downloading or executing any installer.
- Document the installer’s filesystem changes, network access, installed binaries, requested permissions, and uninstall procedure.
