T03 · Remote Payload Retrieval and Execution
- Location
scripts/install_todo_cli.sh:25- Finding
Unpinned Remote Source Is Built and Installed with Elevated Privileges
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_todo_cli.sh:25-26
Additional Location:SKILL.md:26-29
Vulnerability Type: Mutable remote payload retrieval followed by privileged installation
Risk Level: HighComplete Code Snippet:
bash git clone --depth 1 https://github.com/todotxt/todo.txt-cli.git "$tmp_dir/todo.txt-cli" (cd "$tmp_dir/todo.txt-cli" && make && sudo make install)The equivalent manual fallback in
SKILL.mdis:shell git clone https://github.com/todotxt/todo.txt-cli.git cd todo.txt-cli make sudo make install cp -n /usr/local/etc/todo/config ~/.todo/configTechnical Analysis
The Linux installation process clones the mutable default branch of an external Git repository without pinning a reviewed release tag or immutable commit. It performs no checksum or signature verification before invoking the remotely supplied build system.
Running
makeexecutes instructions controlled by the downloaded repository. The subsequentsudo make installexecutes the upstream installation target with root privileges. As a result, the effective code executed by the Skill can change after the Skill itself has been reviewed.Retrieving the official todo.txt repository is relevant to the declared functionality, but compiling mutable remote content and granting its installation process root access exceed the minimum privileges needed to manage a user-owned
todo.txtfile. The installer could instead install a verified version into a user-owned directory.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the mutable default branch.
- The attacker modifies the build or installation instructions to execute malicious commands.
- A user invokes the Skill on a Linux system where
todo.shis unavailable. - Following
SKILL.md, the Agent automatically runsscripts/install_todo_cli.sh. - The insta ...[truncated 972 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed release and immutable commit rather than cloning the default branch.
- Download a fixed release artifact and verify its cryptographic checksum or maintainer signature before executing any build step.
- Avoid
sudo make install. Install the CLI into a user-owned location such as~/.local/binand its configuration into a user-owned directory. - If privileged installation is unavoidable, inspect and constrain the exact files being installed rather than executing an upstream Make target as root.
- Require explicit informed user confirmation before network retrieval, compilation, or privilege elevation.
- Display the exact pinned version, source URL, expected integrity value, and intended installation paths.
- Keep the bundled installer and the manual instructions in
SKILL.mdsynchronized so the fallback does not reintroduce the unsafe path.
