T03 · Remote Payload Retrieval and Execution
- Location
README.md:31- Finding
Unpinned Remote Installer Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent data-collection purpose, but it needs Review because it tells users to run an unverified remote installer and handles API credentials insecurely.
Review the skill before installing. Do not run the `curl | bash` installer unless you have independently verified PinchTab and the exact installer contents. Prefer setting `APIFY_TOKEN` through a secure environment or secret manager, keep `.env` out of source control with restrictive permissions, and run scraping/browser automation only on data and accounts you are authorized to use.
README.md:31Unpinned Remote Installer Executed Directly by Bash
scripts/competitor-monitor.sh:28Competitor Identifier Allows Output Path Traversal
skill.md:360Apify API Token Stored in an Unprotected Plaintext Environment File
The README instructs users to download and immediately execute a remote shell script via curl piped to bash. This bypasses review and integrity verification, so if the hosting site, network path, or script is compromised, arbitrary code will run on the user's machine with the user's privileges.
npm install -g @apify/mcpc
# PinchTab
curl -fsSL https://pinchtab.com/install.sh | bash
# 配置
export APIFY_TOKEN=your_token
The use of '| bash' creates a command chain that executes untrusted remote content immediately, eliminating opportunities for user inspection or policy controls. In the context of a skill README, this is especially risky because it normalizes unsafe installation behavior for users who may copy and run the command verbatim.
npm install -g @apify/mcpc
# PinchTab
curl -fsSL https://pinchtab.com/install.sh | bash
# 配置
export APIFY_TOKEN=your_token
The script imports APIFY_TOKEN from .env using export $(grep APIFY_TOKEN .env | xargs), which is unsafe parsing. A crafted .env line can inject additional shell words or malformed assignments, leading to unintended environment manipulation and potentially unsafe behavior in subsequent commands. In a data-automation skill that users may run locally, trusting and loosely parsing a local file increases risk if the repository or working directory is untrusted.
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
if [ -f .env ]; then
export $(grep APIFY_TOKEN .env | xargs)
else
echo "❌ 错误: 未设置 APIFY_TOKEN"
This finding refers to the same unsafe credential-loading block that reads .env with grep and xargs. While the script does not appear to steal credentials, its method of loading secrets is brittle and can allow unintended shell/environment effects from a malicious or malformed .env file. Because the token is then used for authenticated outbound requests, compromise of this value or shell state could affect external service access.
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
if [ -f .env ]; then
export $(grep APIFY_TOKEN .env | xargs)
else
echo "❌ 错误: 未设置 APIFY_TOKEN"
exit 1
The script loads APIFY_TOKEN from .env using export $(grep APIFY_TOKEN .env | xargs), which is an unsafe pattern for handling secrets. It can mis-parse crafted .env content, unintentionally export extra variables, and expose the workflow to environment manipulation if the local .env file is attacker-controlled or untrusted.
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
if [ -f .env ]; then
export $(grep APIFY_TOKEN .env | xargs)
else
echo "❌ 错误: 未设置 APIFY_TOKEN"
This finding refers to the same unsafe secret-loading behavior from the local .env file. In the context of a data-collection script that will often be run in varied local environments, trusting a nearby .env file without validation increases the risk of accidental secret exposure or shell/environment manipulation.
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
if [ -f .env ]; then
export $(grep APIFY_TOKEN .env | xargs)
else
echo "❌ 错误: 未设置 APIFY_TOKEN"
echo "请设置环境变量: export APIFY_TOKEN=your_token"
The skill instructs users to write an API token directly into a plaintext .env file and then load it into the shell. While common in development, this creates credential exposure risk through accidental commits, insecure file permissions, shell history leakage, or reuse in shared workspaces.
npm install -g @apify/mcpc
# 2. 配置 Token
echo "APIFY_TOKEN=your_token_here" > .env
# 3. 验证
export $(grep APIFY_TOKEN .env | xargs) && mcpc --version
Loading APIFY_TOKEN from a local .env file using shell expansion normalizes insecure credential handling and may expose the token in shared or poorly secured environments. The danger is increased because the skill repeatedly encourages this pattern as standard practice.
echo "APIFY_TOKEN=your_token_here" > .env
export $(grep APIFY_TOKEN .env | xargs) && mcpc --version
**标准工作流:**
This command combines reading a token from .env and passing it as a Bearer header for remote API calls. Although functional, it exposes users to credential mishandling and makes it easy to run authenticated scraping operations without emphasizing secure token lifecycle management.
# 快速预览(仅显示结果,不保存文件)
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="compass/crawler-google-places" \
The example repeats insecure token-loading behavior while exporting collected results to local files, increasing the chance of both credential exposure and storage of scraped data without safeguards. This is particularly risky in collaborative repositories or analyst machines where outputs may be synced or committed.
input:='{"searchStrings": ["coffee shop"], "location": "New York"}'
# 导出 CSV
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="compass/crawler-google-places" \
The same token handling pattern is used for JSON export workflows, reinforcing insecure secret practices across the skill. Because the skill encourages repeated authenticated scraping, a leaked token could enable unauthorized use of the user's Apify account or quotas.
| jq -r '.content[0].text' > results.csv
# 导出 JSON
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="apify/instagram-profile-scraper" \
This mixed workflow combines browser automation, extracted content, and authenticated API usage while still sourcing the token from .env. In a skill focused on broad data collection and competitor monitoring, insecure credential handling can amplify abuse if the environment or workspace is compromised.
grep -oE '(instagram|facebook|tiktok)\.com/[^" ]+' competitor-content.txt > social-links.txt
# Step 3: 使用 Apify 分析其社交媒体
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="apify/instagram-profile-scraper" \
The lead-generation example encourages authenticated scraping of business data and later local transformation to CSV while using a plaintext token-loading pattern. This creates dual risk: unauthorized account use if the token leaks and uncontrolled persistence of collected contact data.
OUTPUT_FILE="coffee-shops-$(date +%Y%m%d).csv"
# Step 1: Apify 采集 Google Maps
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="compass/crawler-google-places" \
The competitor-monitoring automation repeatedly performs authenticated collection at scale using a token read from .env. Repetition across looped scripts raises operational risk because the token may be broadly reused and the script may be copied into insecure environments.
echo "分析 $competitor..."
# Apify 采集数据
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="apify/instagram-profile-scraper" \
This trend-scraping workflow uses the same insecure credential pattern in a script intended for repeated content-generation tasks. If the token is exposed, an attacker could misuse API access or consume paid resources under the user's account.
# trend-to-content.sh
# Step 1: Apify 采集 TikTok 趋势
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
actor:="clockworks/tiktok-trends-scraper" \
The skill instructs users to fetch a remote installation script over the network and pipe it directly to bash. This is dangerous because it executes unreviewed code immediately, allowing compromise if the source is malicious, hijacked, or tampered with in transit or at origin.
npm install -g @apify/mcpc
# 2. PinchTab 浏览器自动化
curl -fsSL https://pinchtab.com/install.sh | bash
# 3. 配置环境变量
cat > .env << EOF
Piping curl output into bash is a classic command-chaining anti-pattern that removes any review barrier between remote content retrieval and local execution. In a skill file meant to be copied by users, this pattern materially increases the chance of arbitrary code execution on the analyst's machine.
npm install -g @apify/mcpc
# 2. PinchTab 浏览器自动化
curl -fsSL https://pinchtab.com/install.sh | bash
# 3. 配置环境变量
cat > .env << EOF
The install section explicitly instructs creation of a plaintext .env containing a live API token. Because installation steps are often copy-pasted verbatim, this is one of the highest-risk credential-handling examples in the file and may directly lead to secret leakage via local compromise or source control mistakes.
curl -fsSL https://pinchtab.com/install.sh | bash
# 3. 配置环境变量
cat > .env << EOF
APIFY_TOKEN=your_apify_token_here
PINCHTAB_PORT=9867
EOF
The verification step again loads the token from .env, reinforcing insecure handling throughout the lifecycle from setup to execution. The risk is contextualized by the skill's intended use in automation-heavy environments where secrets often propagate into scripts and shared workspaces.
# 验证 Apify
export $(grep APIFY_TOKEN .env | xargs) && mcpc --version
# 验证 PinchTab
pinchtab --version
The one-line pipeline combines token loading, authenticated remote execution, JSON processing, and analysis, making it easy to run powerful operations without reviewing security implications. Such convenience pipelines can spread quickly and normalize poor credential hygiene.
# 数据采集 + 分析一站式
export $(grep APIFY_TOKEN .env | xargs) && \
mcpc --json mcp.apify.com \
--header "Authorization: Bearer $APIFY_TOKEN" \
tools-call run-actor \
This markdown file promotes cloud scraping, local Chrome control, and an install-via-curl shell command, but does not include any user-facing warning about effects on privacy, collected third-party data, or system changes. Under the markdown criteria for SQP-2, skill descriptions should warn when behavior could affect user data, privacy, or system integrity.
Comments and runtime output such as error and status messages are written only in Chinese, with no option for the user to select another language. The policy requires avoiding forced language or locale choices unless explicitly justified or opt-in.
This shell script sends each competitor username to mcp.apify.com and includes the APIFY_TOKEN in the Authorization header. Although the script prints progress messages, it does not disclose to the user that data is being sent to a third-party service or that an API credential is used for the request.
The script's comments and terminal output are written in Chinese, which imposes a specific language on users regardless of their locale or preference. The file does not offer any language selection, fallback, or documentation that this is a region-specific tool where Chinese is required.
The skill heavily promotes web scraping, browser automation, token-based API access, and exporting collected data to local files, but it does not give clear user-facing warnings about handling sensitive data, respecting privacy boundaries, or the fact that commands will write files into the working directory. In this context, the omission is risky because the skill is explicitly designed for collecting third-party data at scale, including contact information and emails, which raises privacy, compliance, and accidental data exposure concerns.
No suspicious patterns detected.