T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:37- Finding
Unverified Remote Installer Is Piped Directly into a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37–40
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
markdown Before any other command: 1. If `higgsfield` is not on `$PATH`, install it: ```bash curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | shtext ### Technical Analysis The Skill instructs the agent to retrieve `install.sh` from the mutable `main` branch of an external GitHub repository and stream it directly into `sh`. The remote payload is not pinned to an immutable release or commit, downloaded for review, or validated using a cryptographic signature or checksum. Consequently, the code that executes can change after the Skill has been reviewed. Although installing the Higgsfield CLI supports the declared image-generation functionality, automatically executing mutable remote code is not the minimum safe privilege or installation mechanism necessary for that purpose. The Skill's `allowed-tools: Bash` setting provides the execution channel required to carry out the instruction. This finding does not establish that the current external installer contains malicious commands. The vulnerability is that the Skill delegates local code execution to an unverified, remotely mutable payload. ### Attack Path 1. A user invokes the Skill for product-image generation. 2. The agent follows the mandatory bootstrap procedure and checks whether `higgsfield` is available on `$PATH`. 3. If the CLI is absent, the agent requests `install.sh` from the external repository's mutable `main` branch. 4. `curl` streams the response directly to `sh`, preventing meaningful review before execution. 5. If the repository, publisher account, release process, or delivered payload has been compromised, attacker-controlled shell commands execute as the account running the agent. Potential exploitation methods include modifying the upstream `main` branch, compromisi ...[truncated 960 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstallation instruction. - Prefer a trusted package manager and pin the CLI to a reviewed version.
- If a standalone installer is required:
- Reference an immutable release artifact or commit rather than
main. - Download the installer to a local file without executing it.
- Verify a publisher signature or a SHA-256 checksum obtained through a trusted channel.
- Review the downloaded script and its subprocesses before execution.
- Execute it only after explicit user approval.
- Reference an immutable release artifact or commit rather than
- Run installation with an unprivileged account and avoid
sudoor system-wide installation unless independently justified. - Restrict filesystem and network access during installation where sandboxing is available.
- Document what the installer changes, which files it writes, and whether it transmits telemetry or credentials.
- For local product images passed through
--image, clearly notify users that the files will be uploaded and obtain confirmation when they may contain sensitive information.
A safer conceptual workflow is:
bash curl -fL -o /tmp/higgsfield-install.sh \ "https://example.invalid/immutable-version/install.sh" printf '%s %s\n' "<trusted-sha256>" "/tmp/higgsfield-install.sh" | sha256sum --check # Review and obtain explicit approval before execution. sh /tmp/higgsfield-install.shThe actual artifact URL and digest must come from a trusted, versioned publisher channel; placeholder values must not be used.
- Remove the
