T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:15- Finding
Automatic Retrieval and Execution of Mutable, Unverified Binaries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–46; automatic execution behavior is documented at lines 93 and 136
Vulnerability Type: Remote payload retrieval and execution without enforced integrity verification
Risk Level: MediumVulnerable Code
yaml "install": [ { "id": "adb-claw-darwin-arm64", "kind": "download", "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-darwin-arm64", "bins": ["adb-claw"], "os": "darwin", "label": "Download adb-claw (macOS Apple Silicon)", }, { "id": "adb-claw-darwin-amd64", "kind": "download", "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-darwin-amd64", "bins": ["adb-claw"], "os": "darwin", "label": "Download adb-claw (macOS Intel)", }, { "id": "adb-claw-linux-amd64", "kind": "download", "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-linux-amd64", "bins": ["adb-claw"], "os": "linux", "label": "Download adb-claw (Linux x86_64)", }, { "id": "adb-claw-linux-arm64", "kind": "download", "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-linux-arm64", "bins": ["adb-claw"], "os": "linux", "label": "Download adb-claw (Linux ARM64)", },Related automatic retrieval and execution statements:
markdown The plugin auto-downloads the adb-claw binary on first session.markdown The binary is installed automatically via the SessionStart hook.Technical Analysis
The installation configuration retrieves platform-specific executable files through mutable GitHub
releases/latestURLs. The downloaded artifact is therefore not cryptographically bound to the skill version that was audited. A future release can change the effective executable payload without requiring any modification to this package.T ...[truncated 2259 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every
releases/latestURL with an immutable, version-specific release URL that matches the declared skill version. - Store an expected SHA-256 digest for each operating-system and architecture combination in the audited installation metadata.
- Verify the downloaded binary against that digest before installation or execution, and fail closed on any mismatch.
- Prefer a cryptographically signed release manifest and verify its signature against a public key pinned in the skill package.
- Bind the skill version, executable version, source commit, checksums, and signatures together in the release process.
- Avoid automatically executing a newly downloaded binary during SessionStart until integrity and authenticity checks succeed.
- Prefer reproducible builds from a pinned source commit so users can independently compare locally built artifacts with published binaries.
- Protect the upstream release workflow with least-privilege tokens, mandatory review, protected tags, hardware-backed multifactor authentication, and artifact attestations.
- Document the verified binary version and digest in logs so users can audit which payload was executed.
- Treat the connected Android device as sensitive: restrict ADB authorization to trusted hosts and disable USB debugging when it is not required.
- Replace every
