T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:20- Finding
Unverified Remote Installer Executed Directly by the Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -LsSf https://astral.sh/uv/install.sh | shTechnical Analysis
The installation instructions download a remotely hosted shell script and immediately pipe it into
sh. The effective code is not contained in the reviewed Skill and can change after publication. No fixed release, cryptographic checksum, signature verification, or separate inspection step is provided.The
uvxprerequisite is relevant to the documented MCP configuration, but executing mutable network content directly is not the minimum-risk installation method. The downloaded script receives all permissions held by the user running the command. Trust in HTTPS does not address compromise of the hosting service, publisher infrastructure, or installer itself.Attack Path
- An attacker compromises the installer endpoint, its publishing process, or another component in the delivery trust chain.
- The attacker replaces or modifies the response from
https://astral.sh/uv/install.sh. - A user follows the Skill instructions and runs the documented command.
curlretrieves the attacker-controlled response and passes it directly tosh.- The payload executes immediately with the invoking user's privileges, without an opportunity for verification or review.
Impact Assessment
Successful exploitation permits arbitrary command execution with the invoking user's privileges. The payload could read or modify user-accessible files, steal credentials and configuration data, install additional software, or alter shell configuration. The instruction does not explicitly invoke administrative elevation, so system-wide privileges are not inherently obtained; the scope is limited to the user's existing permissions unless the user independently runs it as a privileged account.
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstallation pattern. - Prefer an official operating-system package manager or another installation channel that supports version pinning and integrity verification.
- If a standalone artifact is necessary, specify an exact release version and download it to a local file.
- Verify the artifact against a publisher-provided cryptographic signature or pinned checksum before execution.
- Execute the verified installer as a separate command so users can inspect it first.
- Document that installation should occur as an unprivileged user and should not be run with
sudounless a narrowly defined operation explicitly requires it.
- Remove the
