T03 · Remote Payload Retrieval and Execution
- Location
setup.sh:19- Finding
Automatic Installation and Execution of an Unverified Remote Binary
- Content
View full analysis
/dev/null || bash "${CLAUDE_SKILL_DIR}/setup.sh" ``` `setup.sh:19-22`: ```bash elif [[ "$(uname -m)" == "arm64" ]]; then install_step "Downloading pre-built binary (Apple Silicon)" curl -sL https://github.com/jackyun1024/mac-screen-vision/releases/download/v1.0.0/screen-vision-1.0.0-arm64-macos.tar.gz | tar xz -C /usr/local/bin/ chmod +x /usr/local/bin/screen-vision ``` `setup.sh:50-52`: ```bash if screen-vision has "$(hostname -s)" 2>/dev/null || screen-vision list 2>/dev/null | head -1 | grep -q '\['; then ok "Screen Recording permission granted" else ``` ### Technical Analysis The Skill directs the agent to run setup automatically whenever `screen-vision` is absent. On Apple Silicon systems without Homebrew, the setup script streams a remote archive directly from a personal GitHub release into `tar`, which extracts its contents into `/usr/local/bin`. No cryptographic signature, pinned SHA-256 digest, archive manifest, or extracted-file validation is used. A versioned HTTPS URL protects transport confidentiality and integrity under ordinary conditions, but it does not independently establish the provenance or expected content of the release asset. The pipeline also prevents inspection of the complete archive before extraction. After extraction, the script marks the resulting file executable and invokes `screen-vision` during the permission check. Consequently, content controlled through the external release channel becomes locally executable code without an integrity gate. ### Attack Path 1. The `screen-vision` command is absent from the tar ...[truncated 1300 chars]- Remediation
View remediation
