T03 · Remote Payload Retrieval and Execution
- Location
scripts/ensure_env.py:278- Finding
Unverified Remote Bootstrap Script Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ensure_env.py, lines 27 and 278–294
Vulnerability Type: Remote code execution through an unauthenticated bootstrap download
Risk Level: CriticalComplete Code Snippet
python ssl._create_default_https_context = ssl._create_unverified_contextpython get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py") urls = [ "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py", "https://bootstrap.pypa.io/get-pip.py", ] ctx = ssl._create_unverified_context() for url in urls: info(f"尝试下载 get-pip.py: {url}") try: urllib.request.urlretrieve(url, get_pip_path, context=ctx) except Exception as e: print(f" 下载失败: {e}") continue rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)Technical Analysis
The mandatory environment-preparation flow attempts to bootstrap
pipwhen neither an existingpipinstallation norensurepipis available. It downloadsget-pip.pyfrom an external URL and immediately executes the downloaded file with the current Python interpreter.The download explicitly uses
ssl._create_unverified_context(). The module also globally replaces Python's default HTTPS context with an unverified context. Consequently, HTTPS encryption does not authenticate the remote endpoint: a forged, expired, or attacker-controlled certificate is accepted.No signature, pinned digest, or other integrity check is applied before execution. The effective code executed by the Skill can therefore differ from the code reviewed in the project.
This path is reachable because
SKILL.mdrequires the environment check before running queries,scripts/check_env.shandscripts/check_env.ps1invokeensure_env.py, and_ensure_pip()uses this fallback when local bootstrap mechanisms fail.Attack Path
- A user or Agent invokes the mandatory environment check.
- The environment lacks a functional ...[truncated 1290 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the global TLS override:
python ssl._create_default_https_context = ssl._create_unverified_context - Do not create or pass an unverified SSL context to
urlretrieve. Use the platform trust store and fail closed on certificate errors. - Prefer the standard
ensurepipmodule or require administrators to installpipthrough a trusted system package manager rather than downloading executable bootstrap code. - If remote bootstrap remains necessary:
- Download only from a canonical HTTPS endpoint.
- Verify a pinned SHA-256 digest or a trusted digital signature before execution.
- Store the download in a securely created, process-private temporary file.
- Refuse execution if any authenticity or integrity check fails.
- Avoid automatically executing mutable remote content during a mandatory Skill initialization path.
- Remove the global TLS override:
