T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:10- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
markdown If `officecli` is missing: - **macOS / Linux**: `curl -fsSL https://d.officecli.ai/install.sh | bash` - **Windows (PowerShell)**: `irm https://d.officecli.ai/install.ps1 | iex` Verify with `officecli --version` (open a new terminal if PATH hasn't picked up). If install fails, download a binary from https://github.com/iOfficeAI/OfficeCLI/releases.Technical Analysis
The installation instructions retrieve mutable scripts from an external domain and immediately execute them through Bash or PowerShell. The downloaded content is not pinned to a version, saved for inspection, checked against a cryptographic digest, or verified using a publisher signature.
Consequently, the code that executes can differ from the content available when this Skill was reviewed. The external installer scripts are not included in the project, so their behavior cannot be established through this static audit. HTTPS protects transport integrity under normal conditions but does not mitigate compromise of the hosting infrastructure, publication account, DNS/TLS trust chain, or installer release process.
Installation is relevant to the declared PPTX functionality, but direct execution of an unverified network response is not the minimum necessary approach. The document itself identifies downloadable GitHub release artifacts as an alternative.
Attack Path
- An Agent loads the Skill and determines that
officecliis unavailable. - The Agent follows the prescribed setup command.
- An attacker who controls or compromises the installer domain, hosting account, deployment pipeline, DNS resolution, or trusted TLS path modifies the returned script.
curlpipes the response directly to Bash, orirmpasses it directly toiex, without an inspe ...[truncated 1169 chars]
- An Agent loads the Skill and determines that
- Remediation
View remediation
Remediation Suggestions
- Remove both direct execution patterns:
curl ... | bashirm ... | iex
- Pin installation to an exact, immutable OfficeCLI release rather than a mutable installer endpoint.
- Download the release artifact to disk without executing it.
- Publish and verify a SHA-256 or stronger checksum through an independently protected release channel.
- Prefer cryptographic publisher signatures and validate the signing identity before installation.
- Present the artifact source, version, checksum, and intended destination to the user and require explicit approval before installing.
- Install only with the invoking user's permissions unless a specific operation demonstrably requires elevation. Do not request
sudoor administrator access by default. - Prefer a trusted package manager or a vendored, auditable installer whose version and integrity are locked.
- Document the files, PATH changes, network access, and other system modifications performed by installation.
- If a script installer remains necessary, separate retrieval from execution so it can be reviewed first, and fail closed when signature or checksum validation does not succeed.
- Remove both direct execution patterns:
