Back to skill

Security audit

Raspberry Pi

Security checks for vulnerabilities and agentic risk

Overview

This Raspberry Pi guidance is mostly coherent, but it recommends running Docker's remote installer directly through a shell without verification.

Review the Docker installation advice before using this skill. Prefer Docker's signed package repository instructions or download, inspect, and verify any installer before running it, especially on a device that holds important data or runs on your network.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:35
Finding

Unverified Remote Script Downloaded and Executed by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 35
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

Complete Code Snippet:

markdown
- Install via `curl -fsSL https://get.docker.com | sh` — apt version is outdated

Technical Analysis

The installation guidance pipes content retrieved from https://get.docker.com directly into a shell. The response is executed without first saving and reviewing it, pinning it to a known version, or verifying its checksum or cryptographic signature.

Because the remote response can change after this Skill has been reviewed, the command creates a mutable code-execution channel. Although the URL is associated with Docker's convenience installer, the security of execution still depends on the remote server, its delivery infrastructure, DNS resolution, and the host's TLS trust configuration. Compromise of any relevant delivery component could cause arbitrary replacement commands to run locally.

Installing Docker is relevant to the Skill's Docker guidance, but direct execution of an unpinned remote script is not necessary for that functionality and does not follow least-privilege or supply-chain hardening principles.

Attack Path

  1. A user or agent follows the installation instruction in SKILL.md.
  2. curl retrieves the current response from https://get.docker.com.
  3. The pipeline passes the response directly to sh, without an intermediate inspection or integrity-verification step.
  4. If the remote response or its delivery path has been compromised, attacker-controlled shell commands execute with the invoking user's privileges.
  5. The installer may request or use elevated privileges to modify system packages and Docker configuration, increasing the potential scope of compromise.

Impact Assessment

A malicious response could execute arbitrary commands, read or alter data accessible to the invoking user, install ...[truncated 484 chars]

Remediation
View remediation

Remediation Suggestions

Remove the direct curl | sh pipeline. Prefer Docker's documented signed package-repository installation procedure, including:

  1. Download repository signing keys over HTTPS and verify their expected fingerprints through an independent trusted source.
  2. Configure the repository for the Raspberry Pi's explicit architecture and supported operating-system release.
  3. Refresh package metadata and install Docker through the package manager.
  4. Pin package or repository versions where operationally practical.
  5. Avoid automatic privilege elevation; clearly identify which individual commands require administrative access.
  6. If a convenience script must be offered, download it to a local file, verify a publisher-provided cryptographic signature or pinned checksum, review it, and execute it as a separate explicit step.
  7. Remove or qualify the unsupported statement that the APT version is outdated, since repository freshness depends on the configured distribution and repository.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The skill recommends piping a remotely fetched script directly into a shell, which bypasses normal package verification and prevents the user from inspecting what will execute. If the endpoint, network path, or hosting account were ever compromised, users could run attacker-controlled code with elevated privileges during Docker installation.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- ARM images only — `linux/arm64` or `linux/arm/v7`, many images unavailable
- 32-bit OS limits to 3GB RAM — use 64-bit for 4GB+ models
- SD card unsuitable for Docker — volume writes accelerate card death
- Install via `curl -fsSL https://get.docker.com | sh` — apt version is outdated

## Headless Setup
- Configure hostname, WiFi, user in Raspberry Pi Imager — before first boot

Static analysis

No suspicious patterns detected.