Back to skill

Security audit

Higgsfield Product Photoshoot

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its bootstrap step can execute an unverified remote installer on the user's machine before any other action.

Install only if you are comfortable with the Higgsfield CLI being installed from a live GitHub script. Prefer installing the CLI yourself from a pinned or verified release, review what it changes, and be aware that local product images passed with `--image` will be uploaded to Higgsfield for generation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:37
Finding

Unverified Remote Installer Is Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37–40
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

markdown
Before any other command:

1. If `higgsfield` is not on `$PATH`, install it:
   ```bash
   curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh
text

### Technical Analysis

The Skill instructs the agent to retrieve `install.sh` from the mutable `main` branch of an external GitHub repository and stream it directly into `sh`. The remote payload is not pinned to an immutable release or commit, downloaded for review, or validated using a cryptographic signature or checksum.

Consequently, the code that executes can change after the Skill has been reviewed. Although installing the Higgsfield CLI supports the declared image-generation functionality, automatically executing mutable remote code is not the minimum safe privilege or installation mechanism necessary for that purpose. The Skill's `allowed-tools: Bash` setting provides the execution channel required to carry out the instruction.

This finding does not establish that the current external installer contains malicious commands. The vulnerability is that the Skill delegates local code execution to an unverified, remotely mutable payload.

### Attack Path

1. A user invokes the Skill for product-image generation.
2. The agent follows the mandatory bootstrap procedure and checks whether `higgsfield` is available on `$PATH`.
3. If the CLI is absent, the agent requests `install.sh` from the external repository's mutable `main` branch.
4. `curl` streams the response directly to `sh`, preventing meaningful review before execution.
5. If the repository, publisher account, release process, or delivered payload has been compromised, attacker-controlled shell commands execute as the account running the agent.

Potential exploitation methods include modifying the upstream `main` branch, compromisi
...[truncated 960 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh installation instruction.
  2. Prefer a trusted package manager and pin the CLI to a reviewed version.
  3. If a standalone installer is required:
    • Reference an immutable release artifact or commit rather than main.
    • Download the installer to a local file without executing it.
    • Verify a publisher signature or a SHA-256 checksum obtained through a trusted channel.
    • Review the downloaded script and its subprocesses before execution.
    • Execute it only after explicit user approval.
  4. Run installation with an unprivileged account and avoid sudo or system-wide installation unless independently justified.
  5. Restrict filesystem and network access during installation where sandboxing is available.
  6. Document what the installer changes, which files it writes, and whether it transmits telemetry or credentials.
  7. For local product images passed through --image, clearly notify users that the files will be uploaded and obtain confirmation when they may contain sensitive information.

A safer conceptual workflow is:

bash
curl -fL -o /tmp/higgsfield-install.sh \
  "https://example.invalid/immutable-version/install.sh"

printf '%s  %s\n' "<trusted-sha256>" "/tmp/higgsfield-install.sh" |
  sha256sum --check

# Review and obtain explicit approval before execution.
sh /tmp/higgsfield-install.sh

The actual artifact URL and digest must come from a trusted, versioned publisher channel; placeholder values must not be used.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The '| sh' construct creates a direct execution chain from untrusted network content into the shell, removing any opportunity for validation before code runs. In this skill context, that is especially risky because the bootstrap step is presented as a prerequisite before any other command, increasing the likelihood an agent or operator executes it automatically.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

  1. If higgsfield is not on $PATH, install it:
    bash
    curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh
    
  2. If higgsfield account status fails with Session expired / Not authenticated, ask the user to run higgsfield auth login (interactive) and wait for confirmation.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "any request involving a product, brand, or paid social creative," which is much broader than the specific examples around it. This can overlap with many ordinary creative or marketing requests and makes it unclear when this skill should not activate beyond a few listed exclusions.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs fetching and executing a remote install script directly from GitHub via curl pipe to sh. This is dangerous because any compromise of the upstream repository, branch, network path, or script contents would result in arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

  1. If higgsfield is not on $PATH, install it:
    bash
    curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh
    
  2. If higgsfield account status fails with Session expired / Not authenticated, ask the user to run higgsfield auth login (interactive) and wait for confirmation.

Static analysis

No suspicious patterns detected.