T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Unpinned Remote Code Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–52
Vulnerability Type: Unpinned external repository installation and execution
Risk Level: Mediumbash git clone https://github.com/GuyMannDude/mnemo-cortex.git cd mnemo-cortex python -m venv .venv source .venv/bin/activate # Windows: .venv\Scripts\activate pip install -e . mnemo-cortex init # interactive wizard: pick model providers mnemo-cortex start # listens on http://localhost:50001 mnemo-cortex health # verifyTechnical Analysis
The installation procedure clones the mutable default branch of an external GitHub repository and immediately installs it using
pip install -e .. It then executes CLI commands supplied by that installation. The instructions do not pin an immutable commit, verify a release signature or checksum, or require dependency lock-file validation.Consequently, the effective code executed by users can change after this Skill has been reviewed. A compromise of the upstream repository, its maintainer account, its packaging configuration, or its transitive dependencies could introduce arbitrary code into the installation path. Editable installation also leaves execution tied directly to the cloned working tree, increasing the risk that subsequent modifications affect runtime behavior.
No malicious payload is embedded in the audited file, and compromise of the referenced repository was not established. The vulnerability is the unsafe trust and execution model of the documented installation process.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or a dependency consumed during installation.
- The attacker adds malicious behavior to the repository source, Python build configuration, package metadata, CLI entry points, or an unpinned dependency.
- A user follows the Skill instructions and clones the mutable de ...[truncated 1260 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the clone to an immutable, reviewed commit hash rather than the repository’s default branch:
bash git clone https://github.com/GuyMannDude/mnemo-cortex.git cd mnemo-cortex git checkout --detach <reviewed-commit-sha> - Publish the expected commit identifier in
SKILL.mdand update it only after reviewing the corresponding source changes. - Prefer a signed, versioned release artifact and verify its cryptographic signature or SHA-256 checksum before installation.
- Require locked Python dependency versions and hash verification, such as a generated requirements file installed with
pip install --require-hashes. - Avoid editable installation for routine deployments. Build or obtain a reproducible wheel from the reviewed revision and install that fixed artifact.
- Run the service under a dedicated, unprivileged account with access limited to the memory database and required configuration.
- Isolate the service where practical using a container or operating-system sandbox, and do not expose its listening port beyond localhost unless authentication and transport protections are configured.
- Document a verification process covering the repository revision, release signature, dependency lock state, and artifact checksum before any CLI command is executed.
- Pin the clone to an immutable, reviewed commit hash rather than the repository’s default branch:
