T03 · Remote Payload Retrieval and Execution
- Location
references/install/nodejs.md:5- Finding
Unverified Remote Installer Is Piped Directly into Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This debugging skill needs Review because it installs persistent tracing tools, uses unsafe installer patterns, exposes or stores credentials insecurely, and can send detailed runtime data to an external service without enough safeguards.
Review carefully before installing. Use only in a non-production environment with test data, do not copy the Java token into any project, pin and verify packages before running them, avoid curl-to-bash installation, keep API keys out of project files, and confirm what trace data leaves your machine before enabling instrumentation.
references/install/nodejs.md:5Unverified Remote Installer Is Piped Directly into Bash
SKILL.md:153Skill Forces Promotional Attribution into Agent Analysis and Final Output
references/install/mcp-install-anonymous.md:13MCP Server Uses an Unpinned Latest Package with Automatic Approval
references/install/java.md:25Hardcoded GitHub Personal Access Token Is Written into pom.xml
references/install/mcp-install-login.md:11API Keys Are Stored in Plaintext IDE and Agent Configuration Files
references/install/python.md:29Python SDK Wheel Is Installed from GitHub Without Integrity Verification
SKILL.md:109Sensitive Runtime State May Be Transmitted to an External Telemetry Service Without Redaction Controls
The guide embeds what appears to be a concrete GitHub personal access token directly in pom.xml properties and uses it in the repository URL. Hardcoded credentials in installation docs are highly likely to be copied into source control, build logs, or shared configs, enabling unauthorized access to the package repository and possible downstream supply-chain abuse if the token is valid.
The installation instructions include repository access credentials and API-related configuration without any warning about credential handling, storage, or leakage risks. In a developer-facing setup guide, this omission materially increases the chance that users will expose secrets in code repositories, CI pipelines, and local project files.
The guide instructs editing ~/.claude/settings.json, a user-level agent configuration path, to register a local command that will be executed by the agent framework. In the context of an agent skill, directing changes to global agent config is sensitive because it can establish persistent command execution behavior beyond a single project.
Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):
{
The document tells users to edit ~/.codex/config.toml, a global agent configuration file, to add an MCP server command. Because this creates persistent agent-integrated execution of an external package, compromise of the package or misconfiguration could affect all future Codex sessions for the user.
Edit ~/.codex/config.toml:
[mcp_servers.debug-mcp-server]
The instructions include editing ~/.gemini/settings.json, which is a user-level agent configuration directory. In this skill context, modifying global agent config to launch an externally fetched MCP server is more dangerous because it introduces persistent behavior into an AI tool that may be invoked across many repositories and tasks.
Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):
{
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):
{
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit ~/.codex/config.toml:
[mcp_servers.debug-mcp-server]
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):
{
The instructions omit any warning that the command executes unreviewed remote code and may modify the project or system. That omission increases the likelihood that users will run a high-risk command without understanding the trust and supply-chain implications.
Piping a downloaded script directly to bash is a direct remote code execution pattern. Because the script runs with the user's privileges and can modify files, install dependencies, exfiltrate secrets, or alter build/runtime behavior, this is dangerous regardless of the stated debugging purpose.
The use of a shell pipeline into bash is a classic chaining-abuse pattern that turns network retrieval into immediate execution with no review boundary. This significantly raises the blast radius of any compromise of the source URL, transit path, or repository and is especially risky in developer environments that often contain source code and credentials.
Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash
Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.
The instructions direct inserting initialization code into the application's entry point so it executes at every startup, creating persistent runtime behavior rather than one-time debugging assistance. This is especially risky because entry-point injection can affect all application runs, exfiltrate runtime data via the tracer, and is broader than the advertised purpose of diagnosing bugs from traces.
The skill claims to analyze runtime traces, but instructs the agent to modify the target project by installing a third-party SDK, restarting services, and later deleting .syncause. That expands scope from observation to codebase and environment mutation, creating a path for unintended code execution, dependency tampering, service disruption, and destructive cleanup in repositories the user may not expect to be altered.
The skill authorizes creation of auxiliary test files and optional helper scripts, including shell scripts, which broadens its effective capability from trace analysis to arbitrary code generation and execution inside the target project. In an agent setting this increases the attack surface substantially, because helper scripts can modify files, exfiltrate data, invoke network tools, or persist unsafe changes under the guise of debugging.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The guide configures a remote WebSocket endpoint (wss://api.syn-cause.com/codeproxy/ws) for a bytecode transformation plugin without clearly disclosing that code, metadata, traces, or other project-derived data may be transmitted to an external service. In the context of a debugging/trace collection skill, this is especially sensitive because runtime diagnostics can contain source snippets, secrets, stack traces, and proprietary application behavior.
The instructions execute npx -y @syncause/debug-mcp@latest, which fetches and runs code from the network at install/use time, and @latest makes the exact code version non-deterministic. This is risky because users may unknowingly execute newly published or compromised package contents without review or pinning.
The document instructs users to place an API key directly into local configuration files across multiple tools, but does not warn that these files may be readable by other local users, captured in backups, logs, screenshots, or accidentally committed to source control. Embedding long-lived credentials in plaintext config materially increases the chance of credential leakage and unauthorized use of the MCP service.
The guidance explicitly recommends project-level configuration for a credentialed server, which makes accidental repository inclusion and sharing with collaborators more likely. In the context of agent/tool configuration, this is more dangerous because these files are often checked into workspaces or inspected by automation, causing API keys to spread beyond the intended user.
The guide instructs users to download and immediately execute a remote shell script from GitHub, which grants arbitrary code execution in the developer's environment. In the context of a debugging skill, this exceeds passive analysis and creates unnecessary supply-chain and host compromise risk if the script or upstream repository is malicious or later modified.
The guide requires generating and saving an installation patch based on project edits but does not warn that patches can embed proprietary source changes, secrets, paths, or configuration values. In a debugging/telemetry skill, collecting or storing such diffs can expand exposure of sensitive code beyond what is necessary.
The guide directs modification of dependency manifests and source entry files without clearly warning the user that repository files will be changed. This is dangerous in an agent context because users may expect diagnostic assistance, not persistent edits that alter application behavior and deployment artifacts.
The skill includes logic for detecting dependency-management systems, editing manifest files, and installing a remote package, which grants repository modification and code-introduction capabilities unrelated to narrow trace analysis. In a debugging skill, that broader authority increases the blast radius substantially because it enables persistent environment changes and arbitrary third-party code onboarding.
The guide instructs the agent to add and install a third-party tracing SDK from a remote GitHub release URL, which expands the skill from passive debugging into modifying dependencies and introducing new executable code into the target project. In the context of an agent skill, this is dangerous because it can silently introduce supply-chain risk, network access, and persistent code execution capability beyond the stated debugging purpose.
The instructions tell the agent to install a wheel directly from a remote GitHub URL without warning about network access, code execution, or provenance verification. This creates a supply-chain risk because the fetched artifact will execute in the developer environment while the user may not realize the security implications.
No suspicious patterns detected.