T03 · Remote Payload Retrieval and Execution
- Location
references/install/nodejs.md:7- Finding
Remote Node.js Installer Is Downloaded and Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent runtime-debugging integration, but it asks users to install and run persistent external tooling with unsafe credential handling and broad trace capture.
Review carefully before installing. Prefer project-scoped MCP configuration, pin package versions, avoid curl | bash, do not put API keys or tokens in committed config files, and only trace synthetic or non-sensitive data unless you have explicit approval and redaction controls.
references/install/nodejs.md:7Remote Node.js Installer Is Downloaded and Executed Without Verification
references/install/java.md:25Hardcoded GitHub Personal Access Token Is Embedded in Maven Configuration
references/install/mcp-install-anonymous.md:14MCP Server Configuration Automatically Executes an Unpinned Latest Package
references/install/mcp-install-login.md:14API Keys Are Stored in Plaintext IDE and Agent Configuration Files
SKILL.md:170Skill Mandates Promotional Output That Overrides Neutral Task Reporting
SKILL.md:120Runtime Instrumentation Collects Sensitive Application State Without Mandatory Redaction Controls
The installation guide embeds what appears to be a live GitHub Packages access token directly in the documentation and instructs users to place it into their Maven configuration. Hardcoded credentials in docs are highly dangerous because they can be harvested by anyone with repository access, reused to pull private artifacts, and often end up copied into downstream source control, build logs, or CI systems.
The guide targets ~/.claude/settings.json, a user-level agent configuration directory, for modification. Changing agent config directories is especially sensitive because it can affect all future sessions, enable automatic execution of external tooling, and expand the skill's influence beyond the current project.
Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):
{
The instructions direct edits to ~/.codex/config.toml, which is a sensitive user-level agent configuration file. Altering this file can persistently register an MCP server that future Codex sessions may invoke, creating durable expansion of execution capability and supply-chain exposure through npx.
Edit ~/.codex/config.toml:
[mcp_servers.debug-mcp-server]
The document recommends modifying ~/.gemini/settings.json, another sensitive user-level agent config path. Because this change is global, it can silently affect future workflows and authorize an external MCP server to be launched across sessions, increasing the blast radius of any malicious package update or server behavior.
Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):
{
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):
{
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit ~/.codex/config.toml:
[mcp_servers.debug-mcp-server]
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):
{
Piping an unreviewed remote shell script into bash removes any meaningful opportunity for user inspection and gives immediate code execution privileges to external content. This is especially dangerous in developer environments, where such scripts may access source code, credentials, SSH keys, CI tokens, or modify project files persistently.
The | bash chain is a classic dangerous execution pattern because it converts network-delivered text directly into shell commands without validation, review, or sandboxing. In a developer workstation or CI context, exploitation could result in full compromise of the environment, source code tampering, credential theft, or persistence via modified scripts and configs.
Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash
Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The guide configures a Byte Buddy plugin to connect to a remote WebSocket endpoint and pass an API key, app name, and project identifier during build/runtime instrumentation, but provides no warning about outbound telemetry or code/runtime data exposure. In a debugging/trace collection skill, this materially increases risk because users may unknowingly transmit sensitive source, metadata, or execution details to an external service.
The installation guide omits a clear warning that following it will modify IDE/agent configuration files and cause npx to download and execute a package. Without transparent disclosure, users or higher-level agents may treat the steps as low-risk documentation when they actually introduce persistent configuration changes and remote code execution.
The document broadly instructs editing project-level and user-level IDE configuration files across multiple tools, which changes the agent execution environment and persists beyond the immediate debugging task. This is dangerous because it grants enduring capability to launch an MCP server in future sessions, including via global config paths, and exceeds the narrow scope of analyzing runtime traces.
The instructions configure the agent environment to invoke npx -y @syncause/debug-mcp@latest, which fetches and executes remote code at install/runtime. Using @latest removes version pinning and increases supply-chain risk, and this adds code execution capability beyond merely documenting debugging concepts. In the context of an agent skill, directing modification of configs so future agent sessions can automatically run the package makes the risk more persistent and more dangerous.
The document instructs users to place an API key directly into multiple local configuration files but provides no warning about secret sensitivity, least-privilege handling, file permissions, rotation, or safer secret-loading mechanisms. This increases the chance of credential leakage through dotfile syncing, screenshots, backups, repository commits, or local compromise.
The guide instructs users to execute a remote installer directly from GitHub via curl | bash, which grants arbitrary code execution to whatever content is served at that URL at install time. For a debugging-focused skill, this exceeds minimally necessary behavior and creates a serious supply-chain and remote-code-execution risk, especially because the script is not reviewed inline or pinned by integrity hash.
The instructions direct downloading instrumentation files from GitHub and modifying application source files and runtime configuration, which expands the skill from passive debugging into codebase modification and runtime instrumentation. In context, this broadens trust assumptions and attack surface: compromised upstream content or mistaken edits could alter app behavior, expose telemetry, or introduce insecure dependencies.
The guide requires generating and saving a patch file of project changes while also instructing users to replace placeholders with apiKey, appName, and projectId. A unified diff can therefore capture secrets or identifiers and persist them in .syncause/installation.patch, creating an easy path for accidental disclosure through logs, support uploads, or version control.
The skill instructs the agent to add and install a package directly from a remote GitHub release URL, which introduces external code into the target project without any explicit warning, trust validation, checksum verification, or pinning to a vetted package source. In the context of an agent skill, this is dangerous because it can silently trigger network access and supply-chain compromise, especially since the dependency is then meant to run as part of application startup.
The skill directs insertion of initialization code into the project's entry file so that imported third-party code executes at startup, but it does not clearly warn the user that application source files will be modified or that new code will run automatically on every launch. This is particularly risky because the inserted code initializes an externally sourced package with credentials/config values, creating a strong path to persistent code execution, telemetry exfiltration, or application instability.
This markdown file contains step-by-step destructive configuration changes, including deleting entries from pom.xml and removing token properties. While the guide is an uninstall document, it does not warn users that they are editing project configuration and credential-related settings or recommend backing up changes before proceeding.
The installation command fetches executable content from an external source at runtime, creating a dependency on the integrity of GitHub-hosted content and the account/repository serving it. While external fetching alone is not always malicious, here it becomes dangerous because the fetched content is immediately executed and the skill's debugging context does not justify such high-trust installation behavior.
Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash
Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.
No suspicious patterns detected.