T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:97- Finding
Remote Installer Executed Through curl-to-Shell Pipeline
- Content
View full analysis
/dev/null 2>&1; then if [[ -f "$HOME/.local/bin/env" ]]; then # shellcheck disable=SC1090 source "$HOME/.local/bin/env" fi if ! command -v uvx >/dev/null 2>&1; then print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh" exit 1 fi fi ``` ### Technical Analysis The installation instructions direct users to download mutable content from an external URL and pipe it directly into `sh`. No version pinning, signature validation, checksum verification, or opportunity for local inspection is provided. HTTPS protects the connection in transit but does not provide reproducibility or protect against compromise of the upstream domain, hosting account, build pipeline, or delivery infrastructure. Although the shell script does not invoke this command automatically, installation instructions are part of the Skill's operational behavior and explicitly encourage remote code execution. ### Attack Path 1. An attacker compromises the upstream installer, its hosting infrastructure, or its release process. 2. A user follows the documented requirement or the error message emitted by `safe-install.sh`. 3. `curl` retrieves the attacker-controlled response. 4. The response is passed directly to `sh` without integrity verification. 5. The payload executes with all permissions available to the invoking user. ### Impact Assessment A compromised response can execute arbitrary commands under the user's account. This can expose readable files, environment variables, credentials, agent configuration, and workspace content. It can also mod ...[truncated 179 chars]- Remediation
View remediation
