T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Mutable Remote JavaScript Is Retrieved and Executed Without Integrity Verification
- Content
View full analysis
``` ### Technical Analysis The recommended workflow executes JavaScript directly from external hosts without Subresource Integrity verification. In particular, the `jscanify` URL references the mutable `master` branch rather than an immutable release or commit. Consequently, the effective code executed by users can change after this skill has been reviewed. Although the OpenCV URL specifies a version path, it is still remotely hosted and lacks an integrity hash. The security of the resulting page therefore depends on the upstream repositories, maintainers, hosting services, and delivery infrastructure remaining trustworthy. This is a remote payload execution channel rather than evidence that the current upstream files are malicious. ### Attack Path 1. An attacker compromises an upstream repository, maintainer account, CDN account, or relevant delivery infrastructure. 2. The attacker modifies the file served from the mutable `jscanify@master` location, or otherwise alters a remotely served script. 3. A user follows the skill instructions and opens the local document-scanning page. 4. The browser downloads and executes the modified JavaScript in the page's origin. 5. When the user selects or processes a document image, the malicious script can access data made available to the page and transmit it to an attacker-controlled endpoint. ### Impact Assessment Malicious remote JavaScript would execute with the privileges of the browser page. It could read document images explicitly selected or exposed by the user, alter scan results, falsify displayed output, and send accessible document content or meta ...[truncated 313 chars]- Remediation
View remediation
