T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:4- Finding
Unpinned Remote Repository Is Retrieved and Executed During Installation
- Content
View full analysis
/dev/null || { rm -rf "$INSTALL_DIR" git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" } else git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" fi pip install -e . 2>/dev/null || { echo "❌ Install failed"; exit 1; } ``` ### Technical Analysis The installation script clones or updates the current default branch of an external GitHub repository and then runs `pip install -e .` from the retrieved working tree. It does not pin the repository to an audited commit, verify a signed tag, or validate the downloaded content against a trusted cryptographic digest. Consequently, the code executed during installation can differ from the code that existed when this Skill was reviewed. Python package installation can invoke attacker-controlled build backends and packaging hooks. Any malicious changes introduced into the remote repository could therefore execute during `pip install -e .`. No evidence establishes that the repository is currently malicious; the vulnerability is the installer’s unconditional trust and execution of mutable remote content. ### Attack Path 1. An attacker compromises the referenced GitHub repository, its maintainer account, or another mechanism capable of changing its default branch. 2. The attacker adds malicious Python packaging configuration, a build backend, installation hooks, or imported setup code. 3. A user runs the documented command: `bash {baseDir}/scripts/install.sh`. 4. The script retrieves the attacker-modified default branch through `git clone` or `git pull`. 5. The script enters the retrieved ...[truncated 634 chars]- Remediation
View remediation
