T03 · Remote Payload Retrieval and Execution
- Location
README.md:41- Finding
Mutable Remote Installer Is Executed Directly by Bash
- Content
View full analysis
# Installs to ~/.claude/skills/arbitrum-dapp
$ bash <(curl -s https://raw.githubusercontent.com/
hummusonrails/arbitrum-dapp-skill/main/install.sh)
``` ### Technical Analysis The command retrieves `install.sh` from the mutable `main` branch of a personal GitHub repository and passes it directly to Bash through process substitution. It does not pin an immutable commit, verify a checksum or signature, or give the user an opportunity to inspect the downloaded content. Although the version of `install.sh` included in the audited artifact does not contain an overtly malicious payload, the command executes whatever content the remote repository serves at the time of installation. Consequently, the effective payload can change after this audit. The current installer also clones or updates content under `~/.claude/skills`, where it will subsequently be loaded by Claude Code: ```bash if [ -d "$SKILL_DIR" ]; then echo "Updating existing installation..." cd "$SKILL_DIR" git pull origin main else echo "Cloning skill..." git clone "$REPO_URL" "$SKILL_DIR" fi ``` Executing arbitrary remote shell code is not the minimum privilege necessary to install a documentation-based Skill. ### Attack Path 1. An attacker compromises the repository owner’s GitHub account, repository, release process, or `main` branch. 2. The attacker replaces `install.sh` with a malicious shell payload. 3. A user copies the documented one-line installation command. 4. `curl` retrieves the attacker-controlled version without integ ...[truncated 791 chars]- Remediation
View remediation
