T03 · Remote Payload Retrieval and Execution
- Location
skill.md:32- Finding
Mutable Remote Code Is Retrieved and Executed with Privileged Credentials
- Content
View full analysis
Vulnerability Details
File Location:
skill.md:32-40
Vulnerability Type: Remote code retrieval and insecure software supply chain
Risk Level: HighVulnerable Code Snippet
bash git clone https://github.com/eggyrooch-blip/office365-tools && cd office365-tools && pip install -r requirements.txtThe surrounding instructions identify this remote repository as the authoritative implementation and direct the agent to consult its documentation when implementation details are uncertain.
Technical Analysis
The Skill package does not contain the provisioning implementation. Instead, it directs the operator or agent to clone the current state of an external GitHub repository, install its dependency set, and execute its Python CLI.
No immutable commit hash, signed release, checksum, dependency lockfile requirement, package hash verification, or mandatory source review is specified. Consequently, the effective code executed by the Skill can change after this Skill has been reviewed. In addition,
pip install -r requirements.txtmay run package installation or build logic from dependencies selected by the mutable remote repository.This is especially dangerous because the resulting CLI is expected to run where the following sensitive values are available:
- Microsoft Entra application client secret
- Tenant identifier and client identifier
- Adobe User Management API credentials
- SMTP username and password
- Account default-password configuration
The behavior therefore matches both remote payload retrieval and an insecure dependency supply chain.
Attack Path
- An attacker compromises the referenced GitHub account, repository, maintainer credentials, or a dependency named in
requirements.txt. - The attacker adds malicious Python code, malicious package installation logic, or a substituted dependency version.
- An operator follows the Skill instructions and clones the ...[truncated 1061 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the reviewed implementation inside the Skill package whenever feasible.
- If external retrieval is necessary, pin the repository to a reviewed full commit hash rather than a mutable branch or tag.
- Verify a cryptographic checksum or signed release before executing downloaded content.
- Pin every direct and transitive Python dependency to an exact reviewed version.
- Require package hashes, such as through a hash-locked requirements file and
pip --require-hashes. - Install and execute the CLI inside an isolated virtual environment or container with restricted filesystem and network access.
- Do not expose production secrets during installation or initialization.
- Use short-lived credentials and separate least-privilege service principals for Office 365, Adobe, and SMTP.
- Treat remote documentation as untrusted input rather than authoritative agent instructions.
- Perform source and dependency review whenever the pinned revision changes.
