T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:35- Finding
Unverified Remote Script Downloaded and Executed by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 35
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: HighComplete Code Snippet:
markdown - Install via `curl -fsSL https://get.docker.com | sh` — apt version is outdatedTechnical Analysis
The installation guidance pipes content retrieved from
https://get.docker.comdirectly into a shell. The response is executed without first saving and reviewing it, pinning it to a known version, or verifying its checksum or cryptographic signature.Because the remote response can change after this Skill has been reviewed, the command creates a mutable code-execution channel. Although the URL is associated with Docker's convenience installer, the security of execution still depends on the remote server, its delivery infrastructure, DNS resolution, and the host's TLS trust configuration. Compromise of any relevant delivery component could cause arbitrary replacement commands to run locally.
Installing Docker is relevant to the Skill's Docker guidance, but direct execution of an unpinned remote script is not necessary for that functionality and does not follow least-privilege or supply-chain hardening principles.
Attack Path
- A user or agent follows the installation instruction in
SKILL.md. curlretrieves the current response fromhttps://get.docker.com.- The pipeline passes the response directly to
sh, without an intermediate inspection or integrity-verification step. - If the remote response or its delivery path has been compromised, attacker-controlled shell commands execute with the invoking user's privileges.
- The installer may request or use elevated privileges to modify system packages and Docker configuration, increasing the potential scope of compromise.
Impact Assessment
A malicious response could execute arbitrary commands, read or alter data accessible to the invoking user, install ...[truncated 484 chars]
- A user or agent follows the installation instruction in
- Remediation
View remediation
Remediation Suggestions
Remove the direct
curl | shpipeline. Prefer Docker's documented signed package-repository installation procedure, including:- Download repository signing keys over HTTPS and verify their expected fingerprints through an independent trusted source.
- Configure the repository for the Raspberry Pi's explicit architecture and supported operating-system release.
- Refresh package metadata and install Docker through the package manager.
- Pin package or repository versions where operationally practical.
- Avoid automatic privilege elevation; clearly identify which individual commands require administrative access.
- If a convenience script must be offered, download it to a local file, verify a publisher-provided cryptographic signature or pinned checksum, review it, and execute it as a separate explicit step.
- Remove or qualify the unsupported statement that the APT version is outdated, since repository freshness depends on the configured distribution and repository.
