T03 Β· Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Mutable Memphis installer is downloaded and executed directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:57
Additional Location:SKILL.md:430
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash # Option 1: One-liner (RECOMMENDED) curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bashThe same file also recommends executing the Ollama installer:
bash curl -fsSL https://ollama.com/install.sh | sh ollama pull nomic-embed-textTechnical Analysis
These commands pipe network responses directly into a shell. The Memphis installer is retrieved from the mutable
mainbranch of a personal GitHub repository and is not pinned to a reviewed commit or release. Neither command verifies a cryptographic signature or checksum before execution.Consequently, the effective code executed by users can change after this Skill has been reviewed. HTTPS protects transport under normal conditions but does not protect users if the upstream repository, publisher account, release process, or served installer is compromised.
Installing an external CLI may be necessary because this package is documentation-only, but executing an unverified mutable response is not the minimum privilege or minimum trust mechanism necessary. Ollama is explicitly optional and is not required for the Skill's core decision-memory functionality.
Attack Path
- An attacker compromises the Memphis repository, maintainer account, or installation-script publishing process.
- The attacker modifies
install.shon themainbranch to contain malicious shell commands. - A user or agent follows the Skill's recommended installation instructions.
curlretrieves the modified response.bashorshexecutes it immediately, without an inspection or integrity-validation step.- The payload operates with all permissions held by the invoking user and can subsequently attempt privilege e ...[truncated 727 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandcurl | shinstallation patterns. - Pin Memphis to an immutable, reviewed release tag or commit rather than
main. - Download the installer or release artifact to disk as a separate step.
- Publish SHA-256 checksums and preferably signed release manifests.
- Verify the checksum and publisher signature before any execution.
- Show users how to inspect the downloaded installer before running it.
- Prefer a signed package repository or a reproducible, versioned package.
- Mark Ollama clearly as optional and direct users to its platform-specific, signature-verified package installation process.
- Remove all
