T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:10- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
markdown ## Setup If `officecli` is missing: - **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash` - **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex` Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.Technical Analysis
Both installation commands retrieve mutable scripts from
d.officecli.aiand immediately execute the responses with Bash or PowerShell. They provide no opportunity for inspection and perform no version pinning, cryptographic signature validation, or checksum verification.The actual installers are not included in the audited project. Consequently, their behavior, installed files, requested permissions, dependencies, and potential persistence mechanisms cannot be statically assessed. The external server can also change the delivered payload after this Skill has been reviewed.
Installing a DOCX utility may be necessary for the declared functionality, but granting an unverified network response immediate code-execution rights is not the minimum safe mechanism. The GitHub release fallback does not establish the integrity of scripts delivered through the separate custom domain.
Attack Path
- The Skill is activated for a document-related task.
- The required
officecliexecutable is not installed. - An agent or user follows the setup instructions.
- The command retrieves the current installer response from
d.officecli.ai. - Bash or PowerShell executes that response immediately, without integrity verification.
- If the hosting service, publication pipeline, DNS/TLS delivery chain, or installer content is compromised, attacker-controlled commands execute with the privileges of the i ...[truncated 614 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both direct download-to-interpreter pipelines.
- Pin installation to a specific, immutable OfficeCLI release and version.
- Download the artifact separately rather than immediately executing a network response.
- Publish and verify a trusted SHA-256 checksum or cryptographic signature before installation.
- Prefer a reputable package manager with locked versions and integrity metadata where available.
- Require explicit user approval before installing or executing third-party software.
- Document the files, PATH changes, network access, and permissions required by the installer.
- Avoid administrative execution unless a documented installation step strictly requires it.
- If scripts remain necessary, host versioned immutable copies, verify their signatures, and instruct users to inspect them before execution.
