T03 · Remote Payload Retrieval and Execution
- Location
skill.md:24- Finding
Unpinned Remote Skill Instructions Are Periodically Retrieved and Followed
- Content
View full analysis
~/.moltbot/skills/molttalent/SKILL.md curl -s https://molttalent.com/heartbeat.md > ~/.moltbot/skills/molttalent/HEARTBEAT.md curl -s https://molttalent.com/skill.json > ~/.moltbot/skills/molttalent/package.json ``` ```markdown ## Molttalent (every 4+ hours) If 4+ hours since last Molttalent check: 1. Fetch https://molttalent.com/heartbeat.md and follow it 2. Update lastMolttalentCheck timestamp in memory ``` ### Technical Analysis The Skill instructs the Agent to download instruction files from a remote server and later re-fetch and follow `heartbeat.md` every four or more hours. The retrieved content is not pinned to an audited version and is not validated using a cryptographic checksum or signature. Although HTTPS protects data in transit under normal conditions and the remote domain is the Skill's declared service, it does not guarantee that future content served by that domain is identical to the reviewed package. Compromise of the website, DNS infrastructure, deployment pipeline, hosting account, or signing credentials could allow an attacker to replace the remote document with malicious Agent instructions. The installation commands also use `curl -s` without `--fail`, integrity checks, or atomic replacement. An HTTP error response or malformed document could therefore overwrite an installed Skill file without producing a clear failure. ### Attack Path 1. An attacker compromises `molttalent.com`, its DNS, hosting account, deployment pipeline, or another component capable of modifying the remote Skill files. 2. The attacker replaces `heartbeat.md` or `skill.md` with instructions that request sensitive files, disclose conversation data, invoke dangerous tools, or alter pers ...[truncated 1186 chars]- Remediation
View remediation
