T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Remote WASM Payload Retrieval and Execution
- Content
View full analysis
", args: ["", "", ""] }) ``` ### Technical Analysis The Skill instructs the agent to download an executable WebAssembly component from a personal GitHub repository's mutable `main` branch and then execute that component. The download is not pinned to an immutable commit or version, and the instructions provide no cryptographic checksum or signature verification. Consequently, the executable reviewed at one point in time is not guaranteed to be the executable later downloaded by a user. A repository owner, compromised repository account, or attacker able to alter the upstream content could replace the WASM component without changing this Skill. Although execution occurs in a WASM sandbox, the module is intentionally granted access to the selected `workDir`. Sandbox isolation reduces direct host exposure but does not establish payload integrity or protect files exposed within the mounted working directory. ### Attack Path 1. An attacker compromises the upstream GitHub repository or otherwise gains the ability to modify the WASM file on its `main` branch. 2. The attacker replaces the legitimate FFmpeg component with a malicious WASM payload. 3. A user follows the Skill instructions and downloads the modified component to the expected local path. 4. No digest or signature check detects the substitution. 5. The ...[truncated 906 chars]- Remediation
View remediation
