T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:33- Finding
Unverified Remote Installer Download and Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 33–40
Vulnerability Type: Remote payload retrieval and execution through a mutable, unverified dependency
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh | bashThe alternative installation procedure is also unpinned and lacks integrity verification:
bash curl -fsSLO https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh less install.sh # inspect it bash install.sh --add-pathTechnical Analysis
The recommended quick-install command retrieves
install.shfrom the mutablemasterbranch of an external personal GitHub repository and streams it directly intobash. The effective code executed by users can therefore change after the Skill has been reviewed.The project artifact contains only
SKILL.md; it does not include the installer itself. Consequently, the installer's behavior, filesystem changes, subprocesses, downloaded dependencies, and effective privilege requirements cannot be audited from the submitted artifact.No commit hash, versioned release, cryptographic checksum, or digital signature is used to establish the integrity or identity of the downloaded script. HTTPS protects the connection in transit but does not protect against repository compromise, maintainer-account compromise, or later modification of the
masterbranch.The alternative procedure allows manual inspection but does not enforce it or cryptographically bind the inspected file to an approved version. It ultimately executes the same mutable remote script. Remote source retrieval is relevant to installing the declared miner, but direct execution of mutable content is not necessary and exceeds the minimum safe trust boundary for that functionality.
This finding does not establish that the remote script is currently malicious. The vulnerability is the unver ...[truncated 1806 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation command entirely. - Include the installer in the Skill package so its complete behavior can be reviewed together with the documentation.
- If remote distribution is required, use a versioned release artifact rather than the mutable
masterbranch. - Pin the source to a reviewed commit hash and pin every recursive submodule to a reviewed commit.
- Publish an expected SHA-256 or stronger digest through a separately protected release channel and verify it before execution.
- Prefer signed release artifacts and verify the signature against a documented, trusted maintainer key.
- Download the installer to a local file, display it for review, and require explicit human authorization before execution.
- Fail closed when checksum or signature verification fails; do not provide an option that silently bypasses verification.
- Run installation and mining under a dedicated, unprivileged account. Avoid
sudounless a specific operation demonstrably requires it. - Document all expected filesystem modifications, PATH changes, network endpoints, subprocesses, and downloaded dependencies.
- Provide an uninstall procedure that removes installed binaries and reverses configuration changes.
- Use reproducible build instructions where feasible so users can verify that binaries correspond to the pinned source.
- Remove the
