T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:34- Finding
Unverified Remote Installer Is Executed Directly by the Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent photo-art tool, but its install and automation instructions give broad local execution and persistence with insufficient safety controls.
Review this carefully before installing. Avoid the curl-to-sh installer, prefer a pinned and verifiable package version, use least-privilege photo albums, consider environment variables or a platform credential store instead of saving keys to the app database, and only enable launchd scheduling if you understand how to inspect, unload, and remove the LaunchAgent and accept recurring API usage and photo uploads.
SKILL.md:34Unverified Remote Installer Is Executed Directly by the Shell
SKILL.md:118Optional Feature Creates a Persistent macOS LaunchAgent
SKILL.md:29Unpinned Third-Party Package Is Resolved and Executed
SKILL.md:41API Credentials Are Persisted in an Application SQLite Database Without Documented Protection
The documentation instructs users to fetch and execute a remote shell script via curl ... | sh, which gives the remote server immediate code-execution capability on the user's machine. If the hosting domain, network path, or script content is compromised, users can be silently infected with arbitrary malware or have secrets exfiltrated.
curl -LsSf uvx.sh/imagemine/install.sh | sh
Piping downloaded content directly into sh removes any opportunity for inspection and turns any upstream compromise into immediate command execution. In a skill that also asks for API keys and integrates with local photos, this becomes more dangerous because a malicious installer could steal credentials, access personal media, or establish persistence.
curl -LsSf uvx.sh/imagemine/install.sh | sh
uvx/uv tool run commands without ==version create a rug-pull risk.
The skill processes user photos, extracts face/name metadata from Apple Photos, sends image-derived content to external AI providers, and stores run metadata locally, but the description does not present this privacy impact prominently up front. That omission can cause users to expose sensitive personal data, including identities and photo contents, without informed consent.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist
No suspicious patterns detected.